Medium severity6.1NVD Advisory· Published Sep 6, 2018· Updated Jun 17, 2026
CVE-2018-16459
CVE-2018-16459
Description
An unescaped payload in exceljs <v1.6 allows a possible XSS via cell value when worksheet is displayed in browser.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
exceljsnpm | < 1.6.0 | 1.6.0 |
Affected products
3- https://github.com/guyonroche/exceljsv5Range: 1.6.0
Patches
Vulnerability mechanics
References
5- hackerone.com/reports/356809nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-2j2j-8rrv-264gghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-16459ghsaADVISORY
- github.com/nodejs/security-wg/blob/master/vuln/npm/464.jsonghsaWEB
- www.npmjs.com/advisories/733ghsaWEB
News mentions
0No linked articles in our index yet.