CVE-2018-16759: Easycms
Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.
The removeXSS function in App/Common/common.php (called from App/Modules/Index/Action/SearchAction.class.php) in EasyCMS v1.4 allows XSS via an onhashchange event.
Affected products
- Easycms Easycms: version 1.4 only
Published 2018-09-09. Last modified 2026-06-17.