CVE-2018-18717: Eleanor-CMS Eleanor CMS
Medium severity, CVSS 4.8. EPSS: 0.5% chance of exploitation in the next 30 days.
An issue was discovered in Eleanor CMS through 2015-03-19. XSS exists via the ajax.php?direct=admin&file=autocomplete&query=[XSS] URI.
Affected products
- Eleanor-CMS Eleanor CMS: up to and including 2015-03-19
Published 2018-10-29. Last modified 2026-06-17.