{"id":"CVE-2019-18656","details":"Pimcore 6.2.3 has XSS in the translations grid because bundles/AdminBundle/Resources/public/js/pimcore/settings/translations.js mishandles certain HTML elements.","aliases":["GHSA-65p8-5423-fw3x"],"modified":"2026-08-07T15:18:14.087199Z","published":"2019-10-31T17:15:10.570Z","references":[{"type":"FIX","url":"https://github.com/pimcore/pimcore/commit/ca036e9f86bb5cdb3dac0930ec131e5f35e26c5f"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pimcore/pimcore","events":[{"introduced":"053e8625d6a9966cfb29644fbc57c9e4846a1534"},{"last_affected":"053e8625d6a9966cfb29644fbc57c9e4846a1534"},{"fixed":"ca036e9f86bb5cdb3dac0930ec131e5f35e26c5f"}],"database_specific":{"cpe":"cpe:2.3:a:pimcore:pimcore:6.2.3:*:*:*:*:*:*:*","extracted_events":[{"introduced":"6.2.3"},{"last_affected":"6.2.3"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["6.2.3","v6.2.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-18656.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}