CVE-2019-15501: Lsoft Listserv

Medium severity, CVSS 6.1. EPSS: 7.4% chance of exploitation in the next 30 days.

Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter.

Affected products

  • Lsoft Listserv: before 16.5-2018a (fixed in 16.5-2018a)

Published 2019-08-26. Last modified 2026-06-17.