CVE-2018-19646: Imperva Securesphere

Critical severity, CVSS 9.8. EPSS: 3.5% chance of exploitation in the next 30 days.

The Python CGI scripts in PWS in Imperva SecureSphere 13.0.10, 13.1.10, and 13.2.10 allow remote attackers to execute arbitrary OS commands because command-line arguments are mishandled.

Affected products

  • Imperva Securesphere: version 13.0.10 only; version 13.1.10 only; version 13.2.10 only

Published 2018-11-28. Last modified 2026-06-17.