Medium 4.4 Unfixed
2026-04-22≤ 1.19.2
HTTP Headers <= 1.19.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Custom Headers' Plugin Setting
Minimum safe version
1.19.0
Update to 1.19.0 or later to address 5 fixable vulnerabilities
HTTP Headers <= 1.19.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Custom Headers' Plugin Setting
HTTP Headers <= 1.19.2 - Authenticated (Administrator+) CRLF Injection via Custom Header Values
HTTP Headers <= 1.19.2 - Authenticated (Administrator+) External Control of File Name or Path to RCE via 'hh_htpasswd_path' and 'hh_www_authenticate_user' Parameters
CVE-2023-37978
HTTP Headers <= 1.18.11 - Server-Side Request Forgery
CVE-2023-37874
CVE-2023-1208
CVE-2023-1207