Medium severity4.8OSV Advisory· Published Dec 18, 2025· Updated Jun 17, 2026
CVE-2023-53936
CVE-2023-53936
Description
Cameleon CMS 2.7.4 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts into post titles. Attackers can create posts with embedded SVG scripts that execute when other users mouse over the post title, potentially stealing session cookies and executing arbitrary JavaScript.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4<2.7.4+ 2 more
- (no CPE)range: <2.7.4
- (no CPE)range: 0.1.7, 0.2.0, 2.1.1, …
- cpe:2.3:a:tuzitio:camaleon_cms:2.7.4:*:*:*:*:*:*:*
- Range: <2.7.4
Patches
Vulnerability mechanics
References
2- www.exploit-db.com/exploits/51446nvdExploitThird Party Advisory
- www.vulncheck.com/advisories/cameleon-cms-authenticated-persistent-cross-site-scripting-via-post-creationnvdThird Party Advisory
News mentions
0No linked articles in our index yet.