{"id":"CVE-2018-20418","details":"index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab.","aliases":["GHSA-72pf-cvwq-vgqg"],"modified":"2026-08-07T14:58:55.557232Z","published":"2018-12-24T04:29:00.243Z","references":[{"type":"ADVISORY","url":"https://github.com/craftcms/cms/blob/master/CHANGELOG-v3.md"},{"type":"EVIDENCE","url":"https://github.com/rdincel1/Craft-CMS-3.0.25---Cross-Site-Scripting"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/46054/"},{"type":"EVIDENCE","url":"https://www.raifberkaydincel.com/craft-cms-3-0-25-cross-site-scripting-vulnerability.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/craftcms/cms","events":[{"introduced":"30b95277d526af7aeff4a10c23b583fde0adb383"},{"last_affected":"30b95277d526af7aeff4a10c23b583fde0adb383"}],"database_specific":{"cpe":"cpe:2.3:a:craftcms:craft_cms:3.0.25:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.0.25"},{"last_affected":"3.0.25"}],"source":"CPE_STRING"}}],"versions":["3.0.25"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-20418.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/nystudio107/craft-seomatic","events":[{"introduced":"38cbb3f414b56ba0f8331b74950778f595383fa1"},{"last_affected":"38cbb3f414b56ba0f8331b74950778f595383fa1"}],"database_specific":{"source":"CPE_STRING","cpe":"cpe:2.3:a:craftcms:craft_cms:3.0.25:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.0.25"},{"last_affected":"3.0.25"}]}}],"versions":["3.0.25"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-20418.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"}]}