CVE-2018-5124: Mozilla Firefox

Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.

Unsanitized output in the browser UI leaves HTML tags in place and can result in arbitrary code execution in Firefox before version 58.0.1.

Affected products

  • Mozilla Firefox: before 58.0.1 (fixed in 58.0.1)

Published 2019-04-26. Last modified 2026-06-17.