Record summary

CVE-2023-53936 has a selected CVSS score of 5.1 (medium); EIP currently links 1 catalogued exploit.

Description

Cameleon CMS 2.7.4 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts into post titles. Attackers can create posts with embedded SVG scripts that execute when other users mouse over the post title, potentially stealing session cookies and executing arbitrary JavaScript.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 18, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List2.7.4affected

Proofs of concept

1

Catalogued exploits

ExploitDBCameleon CMS 2.7.4 - Persistent Stored XSS in Post TitleExploitDB exploitby Yasin GerginNot analyzed1 file
ExploitDB

PoC details

References

4