CVE-2017-7535: Theforeman Foreman

Medium severity, CVSS 6.1. EPSS: 1.5% chance of exploitation in the next 30 days.

foreman before version 1.16.0 is vulnerable to a stored XSS in organizations/locations assignment to hosts. Exploiting this requires a user to actively assign hosts to an organization that contains html in its name which is visible to the user prior to taking action.

Affected products

  • Theforeman Foreman: before 1.16.0 (fixed in 1.16.0)

Published 2018-07-26. Last modified 2026-06-17.