CVE-2019-18219: Sitemagic

Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.

Sitemagic CMS 4.4.1 is affected by a Cross-Site-Scripting (XSS) vulnerability, as it fails to validate user input. The affected components (index.php, upgrade.php) allow for JavaScript injection within both GET or POST requests, via a crafted URL or via the UpgradeMode POST parameter.

Affected products

Published 2019-10-23. Last modified 2026-06-17.