MEDIUM
woylie
CVE published 2026-08-27
CVE-2026-66353
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in woylie doggo allows Reflected XSS. The vulnerability affects versions from 0.1.0 before 0.14.8 and is caused by the library's handling of date field values. Affected applications render <.field type='date'> over user-controlled params, allowing attackers to inject malicious code. The vulnerability can be [truncated]