CVE-2018-16459
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.8%
exploitation probability
0.8%top 47% of all CVEs
observed exploitation
nono source reports it
An unescaped payload in exceljs <v1.6 allows a possible XSS via cell value when worksheet is displayed in browser.
Affected products
https://github.com/guyonroche · exceljsReferences
https://hackerone.com/reports/356809