AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2018-12396

MEDIUM · CVSS 6.5 EPSS 2.27%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-02-28 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2018-12396
Severity
MEDIUM
CVSS
6.5
EPSS
2.27%
Firefox

Original Filing — NVD Description

A vulnerability where a WebExtension can run content scripts in disallowed contexts following navigation or other events. This allows for potential privilege escalation by the WebExtension on sites where content scripts should not be run. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.