CVE-2019-13948: Syguestbook a5 Project Syguestbook a5

Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.

SyGuestBook A5 Version 1.2 allows stored XSS because the isValidData function in include/functions.php does not properly block XSS payloads, as demonstrated by a crafted use of the onerror attribute of an IMG element.

Affected products

Published 2019-07-18. Last modified 2026-06-17.