Description Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section. Remediation References CVE-2016-5682 Related Vulnerabilities Drupal Core 4.7.x Cross-Site Scripting (4.7.0 - 4.7.2) WordPress Plugin Simple Login Log SQL Injection (1.1.1) ownCloud Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2017-9338) ATutor Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-6521) WordPress Plugin Simple add pages or posts Cross-Site Request Forgery (1.6) Severity Medium Classification CVE-2016-5682 CWE-707 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Tags Missing Update Known Vulnerabilities