Medium severity5.4OSV Advisory· Published Dec 10, 2018· Updated Jun 17, 2026
CVE-2018-16635
CVE-2018-16635
Description
Blackcat CMS 1.3.2 allows XSS via the willkommen.php?lang=DE page title at backend/pages/modify.php.
Affected products
3- Range: 1.0, 1.0.3, 1.1, …
cpe:2.3:a:blackcat-cms:blackcat_cms:1.3.2:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:blackcat-cms:blackcat_cms:1.3.2:*:*:*:*:*:*:*
- (no CPE)range: =1.3.2
Patches
Vulnerability mechanics
References
1- github.com/security-breachlock/CVE-2018-16635/blob/master/blackcatcms.pdfnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.