← Vulnerability feed

Vulnerability record · CVE-2020-19511 · published 21 June 2021

CVE-2020-19511: Typesettercms typesetter cross-site scripting vulnerability

Typesettercms · Typesetter

Cross Site Scriptiong vulnerability in Typesetter 5.1 via the !1) className and !2) Description fields in index.php/Admin/Classes,

6.1 CVSS 3.1 Medium EPSS 0.83% · top 44.3% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
0.83%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 2 tagged exploit
5 Jul 2026Last modified by NVD

Description

Cross Site Scriptiong vulnerability in Typesetter 5.1 via the !1) className and !2) Description fields in index.php/Admin/Classes,

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-19511 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2022-25523Typesettercms typesetter cross-site request forgery vulnerabilityTypesetterCMS v5.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which is exploited via a crafted POST request.EPSS 0.55%8.8CVE-2018-6889Typesettercms typesetter code injection vulnerabilityAn issue was discovered in Typesetter 5.1. It suffers from a Host header injection vulnerability, Using this attack, a malicious user can poison the …EPSS 6.7%8.0CVE-2018-6888Typesettercms typesetter cross-site request forgery vulnerabilityAn issue was discovered in Typesetter 5.1. The User Permissions page (aka Admin/Users) suffers from critical flaw of Cross Site Request forgery: usin…EPSS 1.9%7.2CVE-2020-25790Typesettercms typesetter unrestricted file upload vulnerabilityTypesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archive. NOTE: the vendor disputes…EPSS 16%5.4CVE-2018-16639Typesettercms typesetter cross-site scripting vulnerabilityTypesetter 5.1 allows XSS via the index.php/Admin LABEL parameter during new page creation.EPSS 0.68%4.8CVE-2025-71164Typesettercms typesetter cross-site scripting vulnerabilityTypesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the Editing component. The images par…EPSS 0.23%4.8CVE-2025-71165Typesettercms typesetter cross-site scripting vulnerabilityTypesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the administrative interface within t…EPSS 0.23%4.8CVE-2025-71166Typesettercms typesetter cross-site scripting vulnerabilityTypesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the administrative interface within t…EPSS 0.23%

Source: NIST National Vulnerability Database (record CVE-2020-19511), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.