ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2019-20041”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2019-20041
Published
2019-12-27
CVSS:
9.8
ShadowTrackr CVSS:
8.2
Summary:
wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.