CVE-2018-1000848: Wampserver

Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.

Wampserver version prior to version 3.1.5 contains a Cross Site Scripting (XSS) vulnerability in index.php localhost page that can result in very low. This attack appear to be exploitable via payload onmouseover. This vulnerability appears to have been fixed in 3.1.5 and later.

Affected products

  • Wampserver Wampserver: before 3.1.5 (fixed in 3.1.5)

Published 2018-12-20. Last modified 2026-06-17.