CVE-2019-10016: Gforge Advanced Server

Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.

GForge Advanced Server 6.4.4 allows XSS via the commonsearch.php words parameter, as demonstrated by a snippet/search/?words= substring.

Affected products

  • Gforge Advanced Server: version 6.4.4 only

Published 2019-03-25. Last modified 2026-06-17.