### [CVE-2019-16130](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16130) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description YII2-CMS v1.0 has XSS in protected\core\modules\home\models\Contact.php via a name field to /contact.html. ### POC #### Reference - https://github.com/weison-tech/yii2-cms/issues/2 - https://github.com/weison-tech/yii2-cms/issues/2 #### Github No PoCs found on GitHub currently.