Craft CMS XSS in RSS widget feed
CVE-2023-33195
6.1MEDIUM
What is CVE-2023-33195?
Craft is a CMS for creating custom digital experiences on the web. A malformed RSS feed can deliver an XSS payload. This issue was patched in version 4.4.6.
Affected Version(s)
cms >= 4.3.0, <= 4.4.5