The html_filter function did not escape single quotes. HTML attributes inside of single quotes could be have code injected. For example, the variable "var" in
<a id='ref' title='[% var | html %]'>
would not be properly escaped. An attacker could insert some limited HTML and JavaScript, for example,
var = " ' onclick='while (true) { alert(1) }'"
Note that arbitrary HTML and JavaScript would be difficult to inject, because angle brackets, ampersands and double-quotes would still be escaped.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to version 3.103.
Vendor Workaround
Attribute values in templates that contain escaped HTML should use double quotes instead of single quotes.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 20 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 20 May 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Toddr
Toddr template::plugin::html |
|
| Vendors & Products |
Toddr
Toddr template::plugin::html |
Wed, 20 May 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 19 May 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Template::Plugin::HTML versions through 3.102 for Perl allows HTML and JavaScript to be injected. The html_filter function did not escape single quotes. HTML attributes inside of single quotes could be have code injected. For example, the variable "var" in <a id='ref' title='[% var | html %]'> would not be properly escaped. An attacker could insert some limited HTML and JavaScript, for example, var = " ' onclick='while (true) { alert(1) }'" Note that arbitrary HTML and JavaScript would be difficult to inject, because angle brackets, ampersands and double-quotes would still be escaped. | |
| Title | Template::Plugin::HTML versions through 3.102 for Perl allows HTML and JavaScript to be injected | |
| Weaknesses | CWE-79 | |
| References |
|
Status: PUBLISHED
Assigner: CPANSec
Published:
Updated: 2026-05-22T06:39:14.682Z
Reserved: 2026-03-28T19:35:11.737Z
Link: CVE-2026-5090
Updated: 2026-05-19T23:25:21.832Z
Status : Deferred
Published: 2026-05-19T22:16:39.003
Modified: 2026-06-17T10:58:25.757
Link: CVE-2026-5090
No data.
OpenCVE Enrichment
Updated: 2026-05-20T15:30:33Z