CVE-2023-33196

MEDIUM

Craft CMS 4.0.1-4.4.6 - Cross-Site Scripting via Review Volumes

Title source: llm
STIX 2.1

Description

Craft is a CMS for creating custom digital experiences. Cross site scripting (XSS) can be triggered by review volumes. This issue has been fixed in version 4.4.7.

Scores

CVSS v3 5.5
EPSS 0.0065
EPSS Percentile 46.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-80 CWE-79
Status published
Products (3)
craftcms/cms 4.0.0-RC1 - 4.4.7Packagist
craftcms/craft_cms 4.0.0 (4 CPE variants)
craftcms/craft_cms 4.0.1 - 4.4.7
Published May 26, 2023
Tracked Since Feb 18, 2026