CVE-2018-20006: Phpok
Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.
An issue was discovered in PHPok v5.0.055. There is a Stored XSS vulnerability via the title parameter to api.php?c=post&f=save (reachable via the index.php?id=book URI).
Affected products
- Phpok Phpok: version 5.0.055 only
Published 2018-12-10. Last modified 2026-06-17.