CVE-2018-19289: Valine.js Valine
Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.
An issue was discovered in Valine v1.3.3. It allows HTML injection, which can be exploited for JavaScript execution via an EMBED element in conjunction with a .pdf file.
Affected products
- Valine.js Valine: version 1.3.3 only
Published 2018-11-15. Last modified 2026-06-17.