CVE-2018-13999: Catfish-CMS Catfish CMS

Medium severity, CVSS 4.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Catfish CMS v4.7.9 allows XSS via the admin/Index/write.html editorValue parameter (aka an article posted by an administrator).

Affected products

Published 2018-07-12. Last modified 2026-06-17.