CVE-2018-12919: Craftedweb Project Craftedweb
Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.
In CraftedWeb through 2013-09-24, aasp_includes/pages/notice.php allows XSS via the e parameter.
Affected products
- Craftedweb Project Craftedweb: up to and including 2013-09-24
Published 2018-06-27. Last modified 2026-06-17.