Blackcat CMS 1.4 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into page content. Attackers can insert JavaScript payloads in the page modification interface that execute when other users view the compromised page.
History

Tue, 16 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Blackcat-cms
Blackcat-cms blackcat Cms
Vendors & Products Blackcat-cms
Blackcat-cms blackcat Cms

Mon, 15 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 15 Dec 2025 20:45:00 +0000

Type Values Removed Values Added
Description Blackcat CMS 1.4 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into page content. Attackers can insert JavaScript payloads in the page modification interface that execute when other users view the compromised page.
Title Blackcat CMS 1.4 Stored Cross-Site Scripting via Page Modification
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-12-15T20:28:24.133Z

Updated: 2025-12-15T21:46:18.111Z

Reserved: 2025-12-15T14:39:05.361Z

Link: CVE-2023-53891

cve-icon Vulnrichment

Updated: 2025-12-15T21:37:18.296Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-15T21:15:52.390

Modified: 2025-12-16T14:10:11.300

Link: CVE-2023-53891

cve-icon Redhat

No data.