AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-19858

HIGH · CVSS 8.6 EPSS 2.60%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-01-30 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.6. See the original NVD description below for full technical details.

CVE
CVE-2018-19858
Severity
HIGH
CVSS
8.6
EPSS
2.60%

Original NVD Description

PrinceXML, versions 10 and below, is vulnerable to XXE due to the lack of protection against external entities. If an attacker passes HTML referencing an XML file (e.g., in an IFRAME element), PrinceXML will fetch the XML and parse it, thus giving an attacker file-read access and full-fledged SSRF.