CVE-2019-5727: Splunk

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

Splunk Web in Splunk Enterprise 6.5.x before 6.5.5, 6.4.x before 6.4.9, 6.3.x before 6.3.12, 6.2.x before 6.2.14, 6.1.x before 6.1.14, and 6.0.x before 6.0.15 and Splunk Light before 6.6.0 has Persistent XSS, aka SPL-138827.

Affected products

  • Splunk Splunk: before 6.6.0 (fixed in 6.6.0); from 6.0.0, before 6.0.15 (fixed in 6.0.15); from 6.1.0, before 6.1.14 (fixed in 6.1.14); from 6.2.0, before 6.2.14 (fixed in 6.2.14); from 6.3.0, before 6.3.12 (fixed in 6.3.12); from 6.4.0, before 6.4.9 (fixed in 6.4.9); …

Published 2019-02-21. Last modified 2026-06-17.