Medium severity6.1GHSA Advisory· Published Mar 21, 2019· Updated Jun 17, 2026
CVE-2018-19917
CVE-2018-19917
Description
Microweber 1.0.8 has reflected cross-site scripting (XSS) vulnerabilities.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
microweber/microweberPackagist | <= 1.0.8 | — |
Affected products
3<= 1.0.8+ 1 more
- (no CPE)range: <= 1.0.8
- cpe:2.3:a:microweber:microweber:1.0.8:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
8- packetstormsecurity.com/files/151005/Microweber-1.0.8-Cross-Site-Scripting.htmlnvdExploitThird Party AdvisoryVDB EntryWEB
- seclists.org/fulldisclosure/2019/Jan/12nvdMailing ListThird Party AdvisoryWEB
- seclists.org/fulldisclosure/2019/Jan/25nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-582j-m369-hj2fghsaADVISORY
- github.com/microweber/microweber/commits/masternvdThird Party Advisory
- nvd.nist.gov/vuln/detail/CVE-2018-19917ghsaADVISORY
- www.netsparker.com/web-applications-advisories/ns-18-038-reflected-cross-site-scripting-in-microweber/nvdThird Party Advisory
- www.netsparker.com/web-applications-advisories/ns-18-038-reflected-cross-site-scripting-in-microweberghsaWEB
News mentions
0No linked articles in our index yet.