CVE-2018-11680: Cmseasy

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue was discovered in CmsEasy 6.1_20180508. There is a CSRF vulnerability in the rich text editor that can add an IFRAME element. This might be used in a DoS attack if a referenced remote URL is refreshed at a rapid rate.

Affected products

Published 2018-06-02. Last modified 2026-06-17.