Textpattern CMS 4.8.8 contains a stored cross-site scripting vulnerability in the article excerpt field that allows authenticated users to inject malicious scripts. Attackers can insert JavaScript payloads into the excerpt, which will execute when the article is viewed by other users.
Metrics
Affected Vendors & Products
References
History
Wed, 24 Dec 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:textpattern:textpattern:4.8.8:-:*:*:*:*:*:* |
Thu, 18 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Dec 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Textpattern
Textpattern textpattern |
|
| Vendors & Products |
Textpattern
Textpattern textpattern |
Wed, 17 Dec 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Textpattern CMS 4.8.8 contains a stored cross-site scripting vulnerability in the article excerpt field that allows authenticated users to inject malicious scripts. Attackers can insert JavaScript payloads into the excerpt, which will execute when the article is viewed by other users. | |
| Title | Textpattern CMS 4.8.8 Authenticated Stored Cross-Site Scripting via Article Excerpt | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-17T22:44:47.932Z
Updated: 2025-12-18T15:04:25.608Z
Reserved: 2025-12-16T19:22:09.994Z
Link: CVE-2023-53911
Updated: 2025-12-18T14:50:53.258Z
Status : Analyzed
Published: 2025-12-17T23:15:49.497
Modified: 2025-12-24T15:17:27.903
Link: CVE-2023-53911
No data.