CVE-2023-53927

MEDIUM

PHPJabbers Simple CMS 5.0 - XSS

Title source: llm

Description

PHPJabbers Simple CMS 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through section name parameters. Attackers can create sections with embedded JavaScript payloads that will execute when administrators view the sections, potentially enabling client-side code execution.

Exploits (1)

exploitdb WORKING POC
by Ahmet Ümit BAYRAM · textwebappsphp
https://www.exploit-db.com/exploits/51415

Scores

CVSS v3 5.4
EPSS 0.0005
EPSS Percentile 15.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
PHPJabbers/Simple CMS 5.0
phpjabbers/simple_cms 5.0
Published Dec 17, 2025
Tracked Since Feb 18, 2026