CVE-2018-20837: Typesettercms Typesetter

Medium severity, CVSS 4.8. EPSS: 0.7% chance of exploitation in the next 30 days.

include/admin/Menu/Ajax.php in Typesetter 5.1 has index.php/Admin/Menu/Ajax?cmd=AddHidden title XSS.

Affected products

Published 2019-05-09. Last modified 2026-06-17.