5.1

CVSS4.0

CVE-2023-53919 - PodcastGenerator Stored Cross-Site Scripting via Freebox Content Field

PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the Freebox content field accessible through the theme customization interface (theme_freebox.php). Malicious JavaScript payloads injected into the Freebox content execute when users visit the application's home page.

πŸ“… Published: Dec. 17, 2025, 10:44 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 10:44 p.m.

5.1

CVSS4.0

CVE-2023-53918 - PodcastGenerator Stored Cross-Site Scripting via Episode Title Field

PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the episode title field accessible through the episodes upload interface (episodes_upload.php). Malicious JavaScript payloads injected into episode titles execute when administrators view the episodes list page (episodes…

πŸ“… Published: Dec. 17, 2025, 10:44 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 10:44 p.m.

5.1

CVSS4.0

CVE-2023-53916 - Zenphoto 1.6 Stored Cross-Site Scripting via User Postal Code Field

Zenphoto 1.6 contains a stored cross-site scripting vulnerability in the user postal code field accessible through the admin-users.php interface. When administrators view user information imported as HTML, malicious JavaScript payloads injected into the postal code field execute in their browser co…

πŸ“… Published: Dec. 17, 2025, 10:44 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 10:44 p.m.

5.1

CVSS4.0

CVE-2023-53915 - Zenphoto 1.6 Stored Cross-Site Scripting via Album Description

Zenphoto 1.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by inserting HTML content into album descriptions. Attackers can create albums with malicious iframe or script tags in the description field that execute when users view…

πŸ“… Published: Dec. 17, 2025, 10:44 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 10:44 p.m.

9.3

CVSS4.0

CVE-2023-53914 - UliCMS 2023.1 Authentication Bypass via Mass Assignment Vulnerability

UliCMS 2023.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin users through mass assignment in the UserController. Attackers can send a crafted POST request to the admin index.php endpoint with specific parameters to generate an administrative a…

πŸ“… Published: Dec. 17, 2025, 10:44 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 10:44 p.m.

6.2

CVSS4.0

CVE-2023-53913 - Rukovoditel 3.3.1 CSV Injection via User Account Export

Rukovoditel 3.3.1 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into the firstname field. Attackers can craft payloads like =calc|a!z| to trigger code execution when an admin exports customer data as a CSV file.

πŸ“… Published: Dec. 17, 2025, 10:44 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 10:44 p.m.

8.5

CVSS4.0

CVE-2023-53912 - USB Flash Drives Control 4.1.0.0 Unquoted Service Path Privilege Escalation

USB Flash Drives Control 4.1.0.0 contains an unquoted service path vulnerability in its service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\USB Flash Drives Control\usbcs.exe' to inject malicious execu…

πŸ“… Published: Dec. 17, 2025, 10:44 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 10:44 p.m.

5.1

CVSS4.0

CVE-2023-53911 - Textpattern CMS 4.8.8 Authenticated Stored Cross-Site Scripting via Article Excerpt

Textpattern CMS 4.8.8 contains a stored cross-site scripting vulnerability in the article excerpt field that allows authenticated users to inject malicious scripts. Attackers can insert JavaScript payloads into the excerpt, which will execute when the article is viewed by other users.

πŸ“… Published: Dec. 17, 2025, 10:44 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 10:44 p.m.

5.1

CVSS4.0

CVE-2023-53910 - WBCE CMS 1.6.1 Stored Cross-Site Scripting via Page Content

WBCE CMS 1.6.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by inserting script tags into page content through the WYSIWYG editor. Attackers can submit POST requests to /wbce/modules/wysiwyg/save.php with malicious script co…

πŸ“… Published: Dec. 17, 2025, 10:44 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 10:44 p.m.

5.1

CVSS4.0

CVE-2023-53909 - WBCE CMS 1.6.1 SVG File Content Cross-Site Scripting

WBCE CMS 1.6.1 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by uploading crafted SVG files through the media manager. Attackers can upload SVG files containing script tags to the /wbce/modules/elfinder/ef/php/connector.wbce.…

πŸ“… Published: Dec. 17, 2025, 10:44 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 10:44 p.m.
Total resulsts: 323515
Page 57 of 32,352
Β« previous page Β» next page
Filters