← Vulnerability feed

Vulnerability record · CVE-2019-18791 · published 13 February 2020

CVE-2019-18791: Lexmark cx31x firmware cross-site scripting vulnerability

Lexmark · Cx31x Firmware

Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. The vulnerability can be exploited to expose session credentials and other information via the users web browser.

5.4 CVSS 3.1 Medium EPSS 0.53% · top 57.4% CWE-79 · Cross-site scripting
5.4CVSS 3.1 base score, v2 3.5
0.53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
80Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web server. The vulnerability can be exploited to expose session credentials and other information via the users web browser.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected products

80 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-18791 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-9930Lexmark cs31x firmware integer overflow vulnerabilityVarious Lexmark products have an Integer Overflow.EPSS 1.5%9.8CVE-2019-9932Lexmark cs31x firmware memory buffer overflow vulnerabilityVarious Lexmark products have a Buffer Overflow (issue 2 of 3).EPSS 1.5%9.8CVE-2019-9933Lexmark cs31x firmware memory buffer overflow vulnerabilityVarious Lexmark products have a Buffer Overflow (issue 3 of 3).EPSS 1.5%9.1CVE-2019-10058Lexmark cs31x firmware vulnerabilityVarious Lexmark products have Incorrect Access Control.EPSS 1.1%7.5CVE-2018-18894Lexmark 6500e firmware path traversal vulnerabilityCertain older Lexmark devices (C, M, X, and 6500e before 2018-12-18) contain a directory traversal vulnerability in the embedded web server.EPSS 1.7%7.5CVE-2011-3269Lexmark x950 firmware information exposure vulnerabilityLexmark X, W, T, E, C, 6500e, and 25xxN devices before 2011-11-15 allow attackers to obtain sensitive information via a hidden email address in a Sca…EPSS 1.1%7.5CVE-2019-9931Lexmark cs31x firmware vulnerabilityVarious Lexmark printers contain a denial of service vulnerability in the SNMP service that can be exploited to crash the device.EPSS 1.1%5.4CVE-2020-10094Lexmark cs31x firmware cross-site scripting vulnerabilityA cross-site scripting (XSS) vulnerability in Lexmark CS31x before LW74.VYL.P273; CS41x before LW74.VY2.P273; CS51x before LW74.VY4.P273; CX310 befor…EPSS 0.65%

Source: NIST National Vulnerability Database (record CVE-2019-18791), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.