Medium severity4.8NVD Advisory· Published Dec 19, 2018· Updated Jun 17, 2026
CVE-2018-19597
CVE-2018-19597
Description
CMS Made Simple 2.2.8 allows XSS via an uploaded SVG document, a related issue to CVE-2017-16798.
Affected products
3= 2.2.8+ 1 more
- (no CPE)range: = 2.2.8
- cpe:2.3:a:cmsmadesimple:cms_made_simple:2.2.8:*:*:*:*:*:*:*
- Range: = 2.2.8
Patches
Vulnerability mechanics
References
1- github.com/security-breachlock/CVE-2018-19597/blob/master/cmssms.pdfnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.