CVE-2018-19516: Kde Applications

Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.

messagepartthemes/default/defaultrenderer.cpp in messagelib in KDE Applications before 18.12.0 does not properly restrict the handling of an http-equiv="REFRESH" value.

Affected products

  • Kde Kde Applications: before 18.12 (fixed in 18.12)

Published 2020-03-12. Last modified 2026-06-17.