CVE-2020-13870: Verbb Comments

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. There is stored XSS via an asset volume name.

Affected products

  • Verbb Comments: before 1.5.5 (fixed in 1.5.5)

Published 2020-06-05. Last modified 2026-06-17.