Medium severity4.8NVD Advisory· Published Jun 27, 2022· Updated Jul 9, 2026
CVE-2022-33009
CVE-2022-33009
Description
A stored cross-site scripting (XSS) vulnerability in LightCMS v1.3.11 allows attackers to execute arbitrary web scripts or HTML via uploading a crafted PDF file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:lightcms_project:lightcms:1.3.11:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:lightcms_project:lightcms:1.3.11:*:*:*:*:*:*:*
- (no CPE)range: = 1.3.11
- LightCMS/LightCMSdescription
Patches
Vulnerability mechanics
References
1- github.com/eddy8/LightCMS/issues/30nvdExploitIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.