CVE-2018-14777: Dleviet Datalife Engine

Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.

An issue was discovered in DataLife Engine (DLE) through 13.0. An attacker can use XSS (related to the /addnews.html and /index.php?do=addnews URIs) to send a malicious script to unsuspecting Admins or users.

Affected products

  • Dleviet Datalife Engine: up to and including 13.0

Published 2018-08-01. Last modified 2026-06-17.