Elgg Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2013-0234
Cross-site scripting (XSS) vulnerability in the Twitter widget in Elgg before 1.7.17 and 1.8.x before 1.8.13 allows remote attackers to inject arbitrary web script or HTML via the paramstwitter_username parameter to action/widgets/save.