CVE-2018-19340: Guriddo Form PHP

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

Guriddo Form PHP 5.3 has XSS via the demos/jqform/defaultnodb/default.php OrderID, ShipName, ShipAddress, ShipCity, ShipPostalCode, ShipCountry, Freight, or details parameter.

Affected products

Published 2018-11-17. Last modified 2026-06-17.