Medium severity4.8OSV Advisory· Published Dec 31, 2018· Updated Jun 17, 2026
CVE-2018-19901
CVE-2018-19901
Description
No-CMS 1.1.3 is prone to Persistent XSS via the blog/manage_article/index/ "article_title" parameter.
Affected products
2- Range: v0.6.6-alpha, v1.1.3, v_0.5.0_stable, …
- cpe:2.3:a:no-cms_project:no-cms:1.1.3:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- github.com/security-breachlock/CVE-2018-19901/blob/master/XSS-1.pdfnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.