CVE-2019-9554: Craft CMS

Medium severity, CVSS 6.1. EPSS: 3.7% chance of exploitation in the next 30 days.

In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at an s/admin/entries/news/new URI.

Affected products

Published 2019-12-31. Last modified 2026-06-17.