Launchpad.net

CVE 2012-4675

Cross-site scripting (XSS) vulnerability in PluXml 5.1.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to file update.

See the CVE page on Mitre.org for more details.