Official Product Homepageproduct
https://github.com/CouchCMS/CouchCMS CVE-2021-47955
MEDIUM
CouchCMS 2.2.1 Cross-Site Scripting via SVG File Upload
Record summary
CVE-2021-47955 has a selected CVSS score of 5.1 (medium); EIP currently links 1 catalogued exploit.
Description
CouchCMS 2.2.1 contains a cross-site scripting vulnerability that allows authenticated attackers to execute arbitrary JavaScript by uploading malicious SVG files through the file upload functionality. Attackers can upload SVG files containing embedded script tags to the browse.php endpoint, which are then executed in users' browsers when the files are accessed or previewed.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 18, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
CouchCMSBrowse CouchCMS / CouchCMS | CVE List | 2.2.1 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBCouchCMS 2.2.1 - Persistent Cross-Site ScriptingExploitDB exploitby xxcddNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-47955 ExploitDB-49636exploit
https://www.exploit-db.com/exploits/49636 VulnCheck Advisory: CouchCMS 2.2.1 Cross-Site Scripting via SVG File UploadThird-party advisory
https://www.vulncheck.com/advisories/couchcms-cross-site-scripting-via-svg-file-upload