---
id: CVE-2018-19943
title: >-
  If exploited, this cross-site scripting vulnerability could allow remote
  attackers to inject malicious code
summary: >-
  If exploited, this cross-site scripting vulnerability could allow remote
  attackers to inject malicious code. QNAP has already fixed these issues in the
  following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261
  build …
severity: high
cvss: 8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H'
cwe:
  - CWE-79
  - CWE-80
  - CWE-79
vendor: qnap
product: qts
affected:
  - qts < 4.2.6
  - 'qts >= 4.3.1.0013, < 4.3.3.1252'
  - 'qts >= 4.3.4, < 4.3.4.1282'
  - 'qts >= 4.3.6, < 4.3.6.1263'
  - 'qts >= 4.4.0, < 4.4.1.1261'
  - 'qts >= 4.4.2, < 4.4.2.1270'
  - qts = 4.2.6
patched:
  - qts 4.4.2.1270
published: '2020-10-28'
updated: '2026-08-13'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2018-19943'
references:
  - url: 'https://www.qnap.com/zh-tw/security-advisory/qsa-20-01'
    label: security@qnapsecurity.com.tw
  - url: 'https://www.qnap.com/zh-tw/security-advisory/qsa-20-01'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-19943
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
epss: 0.17705
epssPercentile: 0.9702
kev: true
kevDateAdded: '2022-05-24'
kevDueDate: '2022-06-14'
kevRansomware: true
exploited: true
zeroDay: true
ingestedAt: '2026-08-13T06:00:54.913Z'
---

## Overview

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build 20200330 and later QTS 4.3.4.1282 build 20200408 and later QTS 4.3.3.1252 build 20200409 and later QTS 4.2.6 build 20200421 and later

## Affected

- `qts < 4.2.6`
- `qts >= 4.3.1.0013, < 4.3.3.1252`
- `qts >= 4.3.4, < 4.3.4.1282`
- `qts >= 4.3.6, < 4.3.6.1263`
- `qts >= 4.4.0, < 4.4.1.1261`
- `qts >= 4.4.2, < 4.4.2.1270`
- `qts = 4.2.6`

## Remediation

Upgrade past the affected range:

- `qts 4.4.2.1270`
