CVE-2018-10854: Red Hat Cloudforms Management Engine
Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.
cloudforms version, cloudforms 5.8 and cloudforms 5.9, is vulnerable to a cross-site-scripting. A flaw was found in CloudForms's v2v infrastructure mapping delete feature. A stored cross-site scripting due to improper sanitization of user input in Name field.
Affected products
- Red Hat Cloudforms Management Engine: version 4.7 only; version 5.8 only; version 5.9 only
Published 2019-11-22. Last modified 2026-06-17.