Stored Cross-Site Scripting in Webedition CMS by Webedition
CVE-2023-53884
Key Information:
- Vendor
Webedition
- Status
- Vendor
- CVE Published:
- 15 December 2025
Badges
What is CVE-2023-53884?
Webedition CMS v2.9.8.8 is susceptible to a stored cross-site scripting vulnerability due to its media upload feature. This flaw permits authenticated users to upload malicious SVG files, which can contain embedded JavaScript. When these files are viewed by other users, the injected scripts are executed, potentially leading to unauthorized actions and data exposure. Admins and users should be aware of this vulnerability and take necessary precautions to mitigate risks associated with SVG uploads.
Affected Version(s)
Webedition CMS 2.9.8.8
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
