CVE-2023-33196

MEDIUM

Craft <4.4.6 - XSS

Title source: llm
STIX 2.1

Description

Craft is a CMS for creating custom digital experiences. Cross site scripting (XSS) can be triggered by review volumes. This issue has been fixed in version 4.4.7.

Scores

CVSS v3 5.5
EPSS 0.0009
EPSS Percentile 26.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-80 CWE-79
Status published
Products (3)
craftcms/cms 4.0.0-RC1 - 4.4.7Packagist
craftcms/craft_cms 4.0.0 (4 CPE variants)
craftcms/craft_cms 4.0.1 - 4.4.7
Published May 26, 2023
Tracked Since Feb 18, 2026