CVE-2018-16759: Easycms

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

The removeXSS function in App/Common/common.php (called from App/Modules/Index/Action/SearchAction.class.php) in EasyCMS v1.4 allows XSS via an onhashchange event.

Affected products

Published 2018-09-09. Last modified 2026-06-17.