Skip to main content

CVE-2018-19943

8.0
HIGHCVSS v3.1 Base Score
7.03%
LOW RiskEPSS (92nd percentile)
KEV

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build 20200330 and later QTS 4.3.4.1282 build 20200408 and later QTS 4.3.3.1252 build 20200409 and later QTS 4.2.6 build 20200421 and later

Published: 10/28/2020
Modified: 11/3/2025
Back to CVE Lookup

ACTIVELY EXPLOITED IN THE WILD

This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Name:

QNAP NAS File Station Cross-Site Scripting Vulnerability

Vendor / Product:

QNAP Network Attached Storage (NAS)

Required Action:

Apply updates per vendor instructions.

Due Date: 6/14/2022(OVERDUE)
Ransomware Campaign Use
Added to KEV:

5/24/2022

Notes:

https://nvd.nist.gov/vuln/detail/CVE-2018-19943

Vulnerability Summary

CVSS v3 Score

8HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

CVSS v2 Score

3.5

AV:N/AC:M/Au:S/C:N/I:P/A:N

EPSS Score (Exploitation Probability)

7.03%LOW Exploitation Risk
92nd percentile

This vulnerability has a 7.03% probability of being exploited in the next 30 days, ranking higher than 92% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-79, CWE-80)

CVE-2026-42897HIGH 8.1

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

5/14/2026
CVE-2026-8221LOW 2.4

A flaw has been found in Devs Palace ERP Online up to 4.0.0. This impacts an unknown function of the file /inventory/item-save. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

5/10/2026
CVE-2026-5324HIGH 7.2

The Brizy – Page Builder plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in all versions up to, and including, 2.8.11 This is due to a combination of missing nonce verification for unauthenticated form submissions, insufficient handling of FileUpload fields when no file is uploaded, and the reversal of security encoding via html_entity_decode() followed by unescaped output in the admin view. The submit_form() function skips nonce verification for non-logged-in users (api.php:198). The handleFileTypeFields() function fails to overwrite user-supplied values when no file is attached. While htmlentities() is applied during storage, html_entity_decode() reverses this on display (form-entries.php:79). The form-data.php template outputs FileUpload values directly in href attributes without esc_url(). This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the form Leads page.

5/2/2026
CVE-2026-7596MEDIUM 4.3

A vulnerability has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this issue is the function data.get of the file .claude/skills/design-system/scripts/generate-slide.py of the component Slide Generator. Such manipulation leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through a pull request but has not reacted yet.

5/1/2026
CVE-2026-6218MEDIUM 4.3

A vulnerability was found in aandrew-me ytDownloader up to 3.20.2. Affected by this issue is the function createTextNode of the component Error Details Panel. The manipulation results in cross site scripting. The attack may be performed from remote. The vendor was contacted early about this disclosure.

4/13/2026

Similar SeverityHIGH