AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2018-1147

MEDIUM · CVSS 5.4 EPSS 1.15%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-05-18 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2018-1147
Severity
MEDIUM
CVSS
5.4
EPSS
1.15%

Original Filing — NVD Description

In Nessus before 7.1.0, a XSS vulnerability exists due to improper input validation. A remote authenticated attacker could create and upload a .nessus file, which may be viewed by an administrator allowing for the execution of arbitrary script code in a user's browser session. In other scenarios, XSS could also occur by altering variables from the Advanced Settings.