CVE-2018-9036: Checksec Canopy

Medium severity, CVSS 4.8. EPSS: 0.5% chance of exploitation in the next 30 days.

CheckSec Canopy 3.x before 3.0.7 has stored XSS via the Login Page Disclaimer, allowing attacks by low-privileged users against higher-privileged users.

Affected products

  • Checksec Canopy: from 3.0.0, up to and including 3.0.6

Published 2018-06-20. Last modified 2026-06-17.