CVE-2019-7410: Galileo CMS Project Galileo CMS

Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.

There is stored cross site scripting (XSS) in Galileo CMS v0.042. Remote authenticated users could inject arbitrary web script or HTML via $page_title in /lib/Galileo/files/templates/page/show.html.ep (aka the PAGE TITLE Field).

Affected products

Published 2020-08-14. Last modified 2026-06-17.