CVE-2020-35275: Coastercms
Medium severity, CVSS 5.4. EPSS: 1.1% chance of exploitation in the next 30 days.
Coastercms v5.8.18 is affected by cross-site Scripting (XSS). A user can steal a cookie and make the user redirect to any malicious website because it is trigged on the main home page of the product/application.
Affected products
- Coastercms Coastercms: version 5.8.18 only
Published 2020-12-21. Last modified 2026-07-09.