CVE-2019-12047: Gridea
Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.
Gridea v0.8.0 has an XSS vulnerability through which the Nodejs module can be called to achieve arbitrary code execution, as demonstrated by child_process.exec and the "<img src=# onerror='eval(new Buffer(" substring.
Affected products
- Gridea Gridea: version 0.8.0 only
Published 2019-05-13. Last modified 2026-06-17.