← Vulnerability feed

Vulnerability record · CVE-2018-6888 · published 12 February 2018

CVE-2018-6888: Typesettercms typesetter cross-site request forgery vulnerability

Typesettercms · Typesetter

An issue was discovered in Typesetter 5.1. The User Permissions page (aka Admin/Users) suffers from critical flaw of Cross Site Request forgery: using a forged HTTP request, a malicious user can lead a user to unknowingly create / delete or modify a user account due to the lack of an anti-CSRF token.

8.0 CVSS 3.0 High EPSS 1.9% · top 20.9% CWE-352 · Cross-site request forgery
8.0CVSS 3.0 base score, v2 6.0
1.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Typesetter 5.1. The User Permissions page (aka Admin/Users) suffers from critical flaw of Cross Site Request forgery: using a forged HTTP request, a malicious user can lead a user to unknowingly create / delete or modify a user account due to the lack of an anti-CSRF token.

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-6888 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2022-25523Typesettercms typesetter cross-site request forgery vulnerabilityTypesetterCMS v5.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which is exploited via a crafted POST request.EPSS 0.55%8.8CVE-2018-6889Typesettercms typesetter code injection vulnerabilityAn issue was discovered in Typesetter 5.1. It suffers from a Host header injection vulnerability, Using this attack, a malicious user can poison the …EPSS 6.7%7.2CVE-2020-25790Typesettercms typesetter unrestricted file upload vulnerabilityTypesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive. NOTE: the vendor disputes…EPSS 16%6.1CVE-2020-19511Typesettercms typesetter cross-site scripting vulnerabilityCross Site Scriptiong vulnerability in Typesetter 5.1 via the !1) className and !2) Description fields in index.php/Admin/Classes,EPSS 0.83%5.4CVE-2018-16639Typesettercms typesetter cross-site scripting vulnerabilityTypesetter 5.1 allows XSS via the index.php/Admin LABEL parameter during new page creation.EPSS 0.68%4.8CVE-2025-71164Typesettercms typesetter cross-site scripting vulnerabilityTypesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the Editing component. The images par…EPSS 0.23%4.8CVE-2025-71165Typesettercms typesetter cross-site scripting vulnerabilityTypesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the administrative interface within t…EPSS 0.23%4.8CVE-2025-71166Typesettercms typesetter cross-site scripting vulnerabilityTypesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the administrative interface within t…EPSS 0.23%

Source: NIST National Vulnerability Database (record CVE-2018-6888), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.