{"api_version":"1","generated_at":"2026-07-24T00:11:50+00:00","cve":"CVE-2016-4875","urls":{"html":"https://cve.report/CVE-2016-4875","api":"https://cve.report/api/cve/CVE-2016-4875.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-4875","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-4875"},"summary":{"title":"CVE-2016-4875","description":"Multiple cross-site scripting (XSS) vulnerabilities in the IVYWE (1) Assist plugin before 1.1.2.test20160906, (2) dataBox plugin before 0.0.0.20160906, and (3) userBox plugin before 0.0.0.20160906 for Geeklog allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.","state":"PUBLISHED","assigner":"jpcert","published_at":"2017-04-14 18:59:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"6.1","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://github.com/ivywe/geeklog-ivywe/commit/fe20a1bccdfec96125ab3d8dbee6ccbd0767c0be","name":"https://github.com/ivywe/geeklog-ivywe/commit/fe20a1bccdfec96125ab3d8dbee6ccbd0767c0be","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"],"title":"[XSS fixed] Assist plugin og: metatag · ivywe/geeklog-ivywe@fe20a1b · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000167.html","name":"http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000167.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"JVNDB-2016-000167 - JVN iPedia","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/ivywe/geeklog-ivywe/commit/3cdb4ebca5746ff1e02b7e434d5722044d1d09d1","name":"https://github.com/ivywe/geeklog-ivywe/commit/3cdb4ebca5746ff1e02b7e434d5722044d1d09d1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"],"title":"[XSS fixed] headercode template ogp url · ivywe/geeklog-ivywe@3cdb4eb · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/93123","name":"http://www.securityfocus.com/bid/93123","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Geeklog IVYWE CVE-2016-4875 Multiple Cross Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://jvn.jp/en/jp/JVN46087986/index.html","name":"http://jvn.jp/en/jp/JVN46087986/index.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"JVN#46087986: Multiple plugins for Geeklog IVYWE edition vulnerable to cross-site scripting","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-4875","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-4875","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"4875","vulnerable":"1","versionEndIncluding":"1.1.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"assist_project","cpe5":"assist_plugin","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"geeklog","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"4875","vulnerable":"1","versionEndIncluding":"0..0.0.20150609","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"databox_project","cpe5":"databox_plugin","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"geeklog","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"4875","vulnerable":"1","versionEndIncluding":"0.0.0.20150918","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"userbox_project","cpe5":"userbox_plugin","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"geeklog","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T00:46:38.521Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/ivywe/geeklog-ivywe/commit/3cdb4ebca5746ff1e02b7e434d5722044d1d09d1"},{"name":"JVNDB-2016-000167","tags":["third-party-advisory","x_refsource_JVNDB","x_transferred"],"url":"http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000167.html"},{"name":"JVN#46087986","tags":["third-party-advisory","x_refsource_JVN","x_transferred"],"url":"http://jvn.jp/en/jp/JVN46087986/index.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/ivywe/geeklog-ivywe/commit/fe20a1bccdfec96125ab3d8dbee6ccbd0767c0be"},{"name":"93123","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/93123"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2016-09-23T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in the IVYWE (1) Assist plugin before 1.1.2.test20160906, (2) dataBox plugin before 0.0.0.20160906, and (3) userBox plugin before 0.0.0.20160906 for Geeklog allow remote attackers to inject arbitrary web script or HTML via unspecified vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-05-15T13:57:01.000Z","orgId":"ede6fdc4-6654-4307-a26d-3331c018e2ce","shortName":"jpcert"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/ivywe/geeklog-ivywe/commit/3cdb4ebca5746ff1e02b7e434d5722044d1d09d1"},{"name":"JVNDB-2016-000167","tags":["third-party-advisory","x_refsource_JVNDB"],"url":"http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000167.html"},{"name":"JVN#46087986","tags":["third-party-advisory","x_refsource_JVN"],"url":"http://jvn.jp/en/jp/JVN46087986/index.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/ivywe/geeklog-ivywe/commit/fe20a1bccdfec96125ab3d8dbee6ccbd0767c0be"},{"name":"93123","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/93123"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"vultures@jpcert.or.jp","ID":"CVE-2016-4875","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in the IVYWE (1) Assist plugin before 1.1.2.test20160906, (2) dataBox plugin before 0.0.0.20160906, and (3) userBox plugin before 0.0.0.20160906 for Geeklog allow remote attackers to inject arbitrary web script or HTML via unspecified vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://github.com/ivywe/geeklog-ivywe/commit/3cdb4ebca5746ff1e02b7e434d5722044d1d09d1","refsource":"CONFIRM","url":"https://github.com/ivywe/geeklog-ivywe/commit/3cdb4ebca5746ff1e02b7e434d5722044d1d09d1"},{"name":"JVNDB-2016-000167","refsource":"JVNDB","url":"http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000167.html"},{"name":"JVN#46087986","refsource":"JVN","url":"http://jvn.jp/en/jp/JVN46087986/index.html"},{"name":"https://github.com/ivywe/geeklog-ivywe/commit/fe20a1bccdfec96125ab3d8dbee6ccbd0767c0be","refsource":"CONFIRM","url":"https://github.com/ivywe/geeklog-ivywe/commit/fe20a1bccdfec96125ab3d8dbee6ccbd0767c0be"},{"name":"93123","refsource":"BID","url":"http://www.securityfocus.com/bid/93123"}]}}}},"cveMetadata":{"assignerOrgId":"ede6fdc4-6654-4307-a26d-3331c018e2ce","assignerShortName":"jpcert","cveId":"CVE-2016-4875","datePublished":"2017-04-14T18:00:00.000Z","dateReserved":"2016-05-17T00:00:00.000Z","dateUpdated":"2024-08-06T00:46:38.521Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-04-14 18:59:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:assist_project:assist_plugin:*:*:*:*:*:geeklog:*:*","versionEndIncluding":"1.1.0","matchCriteriaId":"2E4A1694-64AC-4EBB-B6D7-F9FB582B64E8"},{"vulnerable":true,"criteria":"cpe:2.3:a:databox_project:databox_plugin:*:*:*:*:*:geeklog:*:*","versionEndIncluding":"0..0.0.20150609","matchCriteriaId":"7552DE20-C4A4-433E-8C3B-BB5EB2F123A5"},{"vulnerable":true,"criteria":"cpe:2.3:a:userbox_project:userbox_plugin:*:*:*:*:*:geeklog:*:*","versionEndIncluding":"0.0.0.20150918","matchCriteriaId":"0D0F790A-CF08-4DEA-A519-27B2ECE74FFB"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"4875","Ordinal":"1","Title":"CVE-2016-4875","CVE":"CVE-2016-4875","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"4875","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in the IVYWE (1) Assist plugin before 1.1.2.test20160906, (2) dataBox plugin before 0.0.0.20160906, and (3) userBox plugin before 0.0.0.20160906 for Geeklog allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.","Type":"Description","Title":"CVE-2016-4875"},{"CveYear":"2016","CveId":"4875","Ordinal":"2","NoteData":"2017-04-14","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"4875","Ordinal":"3","NoteData":"2017-05-15","Type":"Other","Title":"Modified"}]}}}