Textpattern CMS 4.8.8 contains a stored cross-site scripting vulnerability in the article excerpt field that allows authenticated users to inject malicious scripts. Attackers can insert JavaScript payloads into the excerpt, which will execute when the article is viewed by other users.
Metrics
Affected Vendors & Products
References
History
Thu, 18 Dec 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Textpattern
Textpattern textpattern |
|
| Vendors & Products |
Textpattern
Textpattern textpattern |
Wed, 17 Dec 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Textpattern CMS 4.8.8 contains a stored cross-site scripting vulnerability in the article excerpt field that allows authenticated users to inject malicious scripts. Attackers can insert JavaScript payloads into the excerpt, which will execute when the article is viewed by other users. | |
| Title | Textpattern CMS 4.8.8 Authenticated Stored Cross-Site Scripting via Article Excerpt | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-17T22:44:47.932Z
Updated: 2025-12-17T22:44:47.932Z
Reserved: 2025-12-16T19:22:09.994Z
Link: CVE-2023-53911
No data.
Status : Received
Published: 2025-12-17T23:15:49.497
Modified: 2025-12-17T23:15:49.497
Link: CVE-2023-53911
No data.