Medium severity6.1NVD Advisory· Published Nov 15, 2018· Updated Jun 17, 2026
CVE-2018-19289
CVE-2018-19289
Description
An issue was discovered in Valine v1.3.3. It allows HTML injection, which can be exploited for JavaScript execution via an EMBED element in conjunction with a .pdf file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
valinenpm | < 1.3.4 | 1.3.4 |
Affected products
2Patches
Vulnerability mechanics
References
4- github.com/xCss/Valine/issues/127nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-hhrp-qm88-xjr3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-19289ghsaADVISORY
- github.com/xCss/Valine/commit/32d4d5e68df804f0eabb1a2bebbbf9459e31c2b7ghsaWEB
News mentions
0No linked articles in our index yet.