← Vulnerability feed

Vulnerability record · CVE-2018-18517 · published 24 October 2018

CVE-2018-18517: Citrix netscaler gateway firmware cross-site scripting vulnerability

Citrix · Netscaler Gateway Firmware

Citrix NetScaler Gateway 10.5.x before 10.5.69.003, 11.1.x before 11.1.59.004, 12.0.x before 12.0.58.7, and 12.1.x before 12.1.49.1 has XSS.

4.8 CVSS 3.0 Medium EPSS 0.83% · top 44.0% CWE-79 · Cross-site scripting
4.8CVSS 3.0 base score, v2 3.5
0.83%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Citrix NetScaler Gateway 10.5.x before 10.5.69.003, 11.1.x before 11.1.59.004, 12.0.x before 12.0.58.7, and 12.1.x before 12.1.49.1 has XSS.

CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.securityfocus.com/bid/105725 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1042023 Third Party AdvisoryVDB Entry
https://support.citrix.com/article/CTX239002 Vendor Advisory
http://www.securityfocus.com/bid/105725 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1042023 Third Party AdvisoryVDB Entry
https://support.citrix.com/article/CTX239002 Vendor Advisory

Track CVE-2018-18517 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-19781Citrix ADC and Gateway directory traversal enabling code executionCitrix Application Delivery Controller (ADC) and Gateway versions 10.5, 11.1, 12.0, 12.1, and 13.0 contain a directory traversal flaw (CWE-22). The t…KEVEPSS 100%analysed6.5CVE-2020-8195Citrix ADC and Gateway improper input validation information disclosureCitrix ADC, Citrix Gateway, and Citrix SD-WAN WAN-OP contain improper input validation that can result in limited information disclosure to low privi…KEVEPSS 33%analysed6.5CVE-2020-8193Citrix ADC and Gateway improper access control allows unauthenticated endpoint accessCitrix ADC, Citrix Gateway, and Citrix SD-WAN WAN-OP contain an improper access control flaw (CWE-284/CWE-287) that lets unauthenticated users reach …KEVEPSS 88%analysed4.3CVE-2020-8196Citrix ADC and Gateway improper access control information disclosureCitrix ADC, Citrix Gateway and Citrix SD-WAN WAN-OP appliances contain an improper access control flaw (CWE-284/CWE-287) that allows limited informat…KEVEPSS 26%analysed10.0CVE-2015-5538Citrix netscaler application delivery controller firmware vulnerabilityMultiple unspecified vulnerabilities in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 132.8, 10.5 be…EPSS 3.2%9.8CVE-2019-18225Citrix application delivery controller firmware vulnerabilityAn issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway before 10.5 build 70.8, 11.x before 11.1 build 63.9, 12.0 before …EPSS 1.5%9.8CVE-2018-7218Citrix application delivery controller firmware vulnerabilityThe AppFirewall functionality in Citrix NetScaler Application Delivery Controller and NetScaler Gateway 10.5 before Build 68.7, 11.0 before Build 71.…EPSS 6.2%9.8CVE-2018-6809Citrix netscaler application delivery controller firmware vulnerabilityNetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to gain privilege on a target syste…EPSS 4.1%

Source: NIST National Vulnerability Database (record CVE-2018-18517), CISA KEV, FIRST EPSS (scores of 2026-10-05). This page is refreshed as NVD updates the record.