Medium severity5.4OSV Advisory· Published Dec 28, 2018· Updated Jun 17, 2026
CVE-2018-16637
CVE-2018-16637
Description
Evolution CMS 1.4.x allows XSS via the page weblink title parameter to the manager/ URI.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
evolutioncms/evolutionPackagist | >= 1.4, < 1.4.6 | 1.4.6 |
Affected products
3Patches
Vulnerability mechanics
References
5- github.com/security-breachlock/CVE-2018-16637/blob/master/evolution_xss_stored.pdfnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-8h24-3cjr-xxmhghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-16637ghsaADVISORY
- github.com/evolution-cms/evolution/commit/2b8aaa6224997155de0fe9440ad106bd98dc4f4bghsaWEB
- github.com/evolution-cms/evolution/issues/788ghsaWEB
News mentions
0No linked articles in our index yet.