CVE-2019-11715: Mozilla Firefox
Medium severity, CVSS 6.1. EPSS: 1.5% chance of exploitation in the next 30 days.
Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certain circumstances. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
Affected products
- Mozilla Firefox: before 60.8.0 (fixed in 60.8.0); before 68.0 (fixed in 68.0)
- Mozilla Thunderbird: before 60.8.0 (fixed in 60.8.0)
Published 2019-07-23. Last modified 2026-06-17.