Medium severity6.1NVD Advisory· Published Nov 6, 2018· Updated Jun 17, 2026
CVE-2018-16474
CVE-2018-16474
Description
A stored xss in tianma-static module versions <=1.0.4 allows an attacker to execute arbitrary javascript.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
tianma-staticnpm | <= 1.0.4 | — |
Affected products
3- cpe:2.3:a:tianma-static_project:tianma-static:*:*:*:*:*:node.js:*:*Range: <=1.0.4
- npm/tianma-staticv5Range: <=1.0.4
Patches
Vulnerability mechanics
References
4- hackerone.com/reports/403692nvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-jhgp-hvj6-x2p2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-16474ghsaADVISORY
- www.npmjs.com/advisories/741ghsaWEB
News mentions
0No linked articles in our index yet.