CVE-2018-16372: Ideacms

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

The issue was discovered in IdeaCMS through 2016-04-30. There is reflected XSS via the index.php?c=content&a=search kw parameter. NOTE: this product is discontinued.

Affected products

  • Ideacms Ideacms: up to and including 2016-04-30

Published 2018-09-03. Last modified 2026-06-17.