MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation" approach, related to a "Cross Site Scripting (XSS)" issue affecting the action=AttachFile (via page name) component.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-7148.json"
[ { "events": [ { "introduced": "0" }, { "last_affected": "1.9.8" } ] } ]