Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-1000559

20
FAUCET Score

CVE-2018-1000559 describes a Cross-Site Scripting (XSS) vulnerability in qutebrowser versions introduced from v0.11.0. This flaw allows an attacker to steal a user's browsing history by injecting JavaScript code through a specially crafted webpage title, which is then rendered on the qute://history page. Rated as Medium severity (CVSS 6.1), the attack requires user interaction to open the malicious page and then the history command. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability. The issue has been addressed in qutebrowser versions v1.3.3 and v1.4.0.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0.11.0, < 1.3.3CPE matchmatch criteria
cpe:2.3:a:qutebrowser:qutebrowser:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

6.1MEDIUM

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
2.7
CvssVersion
3.0

Exploit Intelligence

EPSS Score
1.50%
Probability of exploitation in next 30 days
EPSS Percentile
71.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0150 is in the 84th percentile among its peer group of 26,219 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: qutebrowserFixed in: 1.3.3

Vendor Advisories (1)

pipGHSA-m4fw-77v7-924mmedium

Qutebrowser XSS Vulnerability

Sep 13, 2018

References

github.com / qutebrowser/qutebrowser/commit/4c9360237f186681b1e3f2a0f30c45161cf405c7
PatchThird Party Advisory
github.com / qutebrowser/qutebrowser/commit/5a7869f2feaa346853d2a85413d6527c87ef0d9f
PatchThird Party Advisory
github.com / qutebrowser/qutebrowser/issues/4011
ExploitThird Party Advisory