PyPI: loggerhead

CVE-2011-0728

Safety vulnerability ID: SFTY-20110329-33023

Safety legacy ID: pyup.io-67952

Cross-site scripting (XSS) vulnerability in templatefunctions.py in Loggerhead before 1.18.1 allows remote authenticated users to inject arbitrary web script or HTML via a filename, which is not properly handled in a revision view.

Created at: Apr 29, 2026Updated at: Apr 29, 2026

Overview

Loggerhead XSS via filename

Advisory

Cross-site scripting (XSS) vulnerability in templatefunctions.py in Loggerhead before 1.18.1 allows remote authenticated users to inject arbitrary web script or HTML via a filename, which is not properly handled in a revision view.

Affected Package

Affecting loggerhead package, versions
<1.18.1

Also affects

---

How to Fix

Upgrade
loggerhead
to
1.18.2
or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more