CVE-2021-47716
MEDIUMOrangescrum - XSS
Title source: ruleDescription
Orangescrum 1.8.0 contains multiple cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts through various input parameters. Attackers can exploit parameters like 'projid', 'CS_message', and 'name' to execute arbitrary JavaScript code in victim's browsers by submitting crafted payloads through application endpoints.
Exploits (1)
exploitdb
WORKING POC
by Hubert Wojciechowski · textwebappsmultiple
https://www.exploit-db.com/exploits/50554
Scores
CVSS v3
5.4
EPSS
0.0005
EPSS Percentile
16.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (2)
orangescrum/orangescrum
1.8.0
Orangescrum/orangescrum
1.8.0
Published
Dec 23, 2025
Tracked Since
Feb 18, 2026