Cross-site scripting (XSS) vulnerability in Website Baker CMS before 2.6.4 allows remote attackers to inject arbitrary web script or HTML via a user display name.
| Software | From | Fixed in |
|---|---|---|
| website_baker / website_baker | 2.6.1 | 2.6.1.x |
| website_baker / website_baker | 2.5.2 | 2.5.2.x |
| website_baker / website_baker | 2.6 | 2.6.x |