CVE-2018-19289: Valine.js Valine

Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.

An issue was discovered in Valine v1.3.3. It allows HTML injection, which can be exploited for JavaScript execution via an EMBED element in conjunction with a .pdf file.

Affected products

Published 2018-11-15. Last modified 2026-06-17.