CVE-2019-18209: Etherpad

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Explorer.

Affected products

Published 2019-10-19. Last modified 2026-06-17.