![](https://secure.gravatar.com/avatar/11dee7c7f3806e117229c9b7b0fa1753.jpg?s=120&d=mm&r=g)
20 Dec
2014
20 Dec
'14
5:33 a.m.
I think that history pages in MariaDB Knowledge Base have a cross-site scripting vulnerability because special characters contained in link texts and revision comments are not escaped. For example, this page: https://mariadb.com/kb/en/meta/editing-help/creole-formatting/+history -- 100の人