CVE-2020-35275: Coastercms

Medium severity, CVSS 5.4. EPSS: 1.1% chance of exploitation in the next 30 days.

Coastercms v5.8.18 is affected by cross-site Scripting (XSS). A user can steal a cookie and make the user redirect to any malicious website because it is trigged on the main home page of the product/application.

Affected products

Published 2020-12-21. Last modified 2026-07-09.