Medium severity4.8NVD Advisory· Published May 13, 2019· Updated Jun 17, 2026
CVE-2018-16625
CVE-2018-16625
Description
index.php/Admin/Uploaded in Typesetter 5.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.
Affected products
3- cpe:2.3:a:typesettercms:typesetter:5.1:*:*:*:*:*:*:*
- Typesetter/Typesetterdescription
- Range: <5.1
Patches
Vulnerability mechanics
News mentions
0No linked articles in our index yet.