CVE-2019-16130: HGW168CC Yii-CMS

Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.

YII2-CMS v1.0 has XSS in protected\core\modules\home\models\Contact.php via a name field to /contact.html.

Affected products

Published 2019-09-09. Last modified 2026-06-17.