Medium severity6.1NVD Advisory· Published Aug 30, 2021· Updated Jun 17, 2026
CVE-2020-18125
CVE-2020-18125
Description
A reflected cross-site scripting (XSS) vulnerability in the /plugin/ajax.php component of Indexhibit 2.1.5 allows attackers to execute arbitrary web scripts or HTML.
Affected products
3=2.1.5+ 2 more
- (no CPE)range: =2.1.5
- (no CPE)
- cpe:2.3:a:indexhibit:indexhibit:2.1.5:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- github.com/Indexhibit/indexhibit/issues/20nvdExploitIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.