https://seclists.org/oss-sec/2025/q4/136: [CVE-2019-18860] SQUID-2023:6 Cross Site Scripting in cachemgr.cgi
Published Nov 5, 2025
·Updated
Affected Software
1 affected component
Squid Squid Proxy Cache
Frequently Asked Questions
1
What is CVE-2019-18860?
CVE-2019-18860 is a Cross-Site Scripting vulnerability found in Squid Proxy Cache's cachemgr.cgi interface.
2
What is the severity of CVE-2019-18860?
CVE-2019-18860 is considered a moderate severity vulnerability due to its potential to execute arbitrary JavaScript in the context of the user's browser.
3
How do I fix CVE-2019-18860?
To fix CVE-2019-18860, you should upgrade to the latest Squid Proxy Cache version that includes the patches for this vulnerability.
4
Who is affected by CVE-2019-18860?
CVE-2019-18860 affects all versions of Squid Proxy Cache prior to the patch that addresses this specific vulnerability.
5
When was CVE-2019-18860 disclosed?
CVE-2019-18860 was disclosed in November 2025 as part of the Squid Proxy Cache Security Update Advisory SQUID-2023:6.