CVE-2019-9554: Craft CMS
Medium severity, CVSS 6.1. EPSS: 3.7% chance of exploitation in the next 30 days.
In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at an s/admin/entries/news/new URI.
Affected products
- Craft CMS Craft CMS: version 3.1.12 only
Published 2019-12-31. Last modified 2026-06-17.