CVE-2023-53953
WebsiteBaker 2.13.3 Stored Cross-Site Scripting via Page Creation
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.1EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
19 dic 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
WebsiteBaker 2.13.3 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts when creating web pages. Attackers can craft malicious payloads in page titles that execute arbitrary JavaScript when the page is viewed by other users.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Productos afectados
Websitebaker · WebsiteBaker¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →