Description Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page. Remediation References CVE-2018-18282 Related Vulnerabilities Squid Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-9749) Atlassian Confluence CVE-2023-22505 Vulnerability (CVE-2023-22505) WordPress Plugin Post SMTP-WP SMTP with Email Logs & Mobile App for Failure Alerts-Any SMTP Plus Gmail SMTP, Office 365, Brevo, Mailgun, Amazon SES, Postmark Cross-Site Scripting (2.8.7) WordPress Plugin WordPress Photo Gallery by Gallery Bank SQL Injection (3.0.101) WordPress Plugin PublishPress Capabilities-User Role Access, Editor Permissions, Admin Menus Cross-Site Request Forgery (2.3.1) Severity Medium Classification CVE-2018-18282 CWE-707 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Tags Missing Update Known Vulnerabilities