Loading
Generated remediation guidance and an executive summary. No account required.
Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11 (as used in Pallets Flask and other products) allows remote attackers to inject arbitrary web script or HTML via a field that contains an exception message.
Cite this page
CVE-2016-10516. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2016-10516
Use CWE-79, Palletsprojects vendor hub and Werkzeug product page to widen CVE-2016-10516 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-29361, CVE-2023-46136 and CVE-2024-34069 for nearby disclosures in the same product family.