⚠ Exploited in the wild
Exploitation observed in the wild. Not yet on CISA KEV.

CVE-2020-8191Cross-site Scripting in Citrix Application Delivery Controller Firmware

Severity
6.1MEDIUMNVD
EPSS
91.0%
top 0.36%
CISA KEV
Not in KEV
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedJul 10
Latest updateMay 24

Description

Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows reflected Cross Site Scripting (XSS).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages12 packages

NVDcitrix/gateway_firmware13.013.0-58.30
NVDcitrix/netscaler_gateway_firmware10.510.5-70.18+3
NVDcitrix/sd-wan_wanop10.210.2.7+2

🔴Vulnerability Details

2
GHSA
GHSA-h686-q2xf-663f: Improper input validation in Citrix ADC and Citrix Gateway versions before 132022-05-24
VulnCheck
Citrix application_delivery_controller_firmware Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2020

💥Exploits & PoCs

1
Nuclei
Citrix ADC/Gateway - Cross-Site Scripting

📋Vendor Advisories

2
Citrix
Citrix Application Delivery Controller, Citrix Gateway, and Citrix SD-WAN WANOP appliance Security Update2020-08-17
Citrix
CVE-2020-8191: Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SD2020-07-10

🕵️Threat Intelligence

2
Tenable
CVE-2020-8193, CVE-2020-8195, and CVE-2020-8196: Active Exploitation of Citrix Vulnerabilities2020-07-15
Greynoiseio
NoiseLetter October 2025