CVE-2018-16718: Nih Ncbi Toolbox

Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.

An XSS vulnerability exists in wwwblast.c in the 2.0.7 through 2.2.26 legacy versions of the NCBI ToolBox via a crafted -z1 argument.

Affected products

  • Nih Ncbi Toolbox: from 2.0.7, up to and including 2.2.26

Published 2019-05-02. Last modified 2026-06-17.