Stored Cross-Site Scripting in PodcastGenerator by PodcastGenerator
CVE-2023-53918
Key Information:
- Vendor
Podcastgenerator
- Status
- Vendor
- CVE Published:
- 17 December 2025
Badges
What is CVE-2023-53918?
PodcastGenerator version 3.2.9 has a stored cross-site scripting vulnerability found in the episode title field within the episodes upload interface (episodes_upload.php). This security flaw allows malicious users to inject JavaScript payloads into episode titles, which then execute when administrators access the episodes list page (episodes_list.php). Attackers can exploit this vulnerability to manipulate content and potentially launch further attacks on the system, jeopardizing the integrity of the application's environment.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
PodcastGenerator 3.2.9
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
