CVE-2018-19509: Ens Webgalamb

Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.

wg7.php in Webgalamb 7.0 makes opportunistic calls to htmlspecialchars() instead of using a templating engine with proper contextual encoding. Because it is possible to insert arbitrary strings into the database, any JavaScript could be executed by the administrator, leading to XSS.

Affected products

  • Ens Webgalamb: version 7.0 only

Published 2019-03-21. Last modified 2026-06-17.