Blackcat CMS 1.4 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into page content. Attackers can insert JavaScript payloads in the page modification interface that execute when other users view the compromised page.
References
| Link | Resource |
|---|---|
| https://blackcat-cms.org/ | Product |
| https://www.exploit-db.com/exploits/51604 | Exploit Third Party Advisory VDB Entry |
| https://www.vulncheck.com/advisories/blackcat-cms-stored-cross-site-scripting-via-page-modification | Third Party Advisory |
| https://www.exploit-db.com/exploits/51604 | Exploit Third Party Advisory VDB Entry |
Configurations
History
17 Dec 2025, 15:35
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:blackcat-cms:blackcat_cms:1.4:*:*:*:*:*:*:* | |
| First Time |
Blackcat-cms blackcat Cms
Blackcat-cms |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
| References | () https://blackcat-cms.org/ - Product | |
| References | () https://www.exploit-db.com/exploits/51604 - Exploit, Third Party Advisory, VDB Entry | |
| References | () https://www.vulncheck.com/advisories/blackcat-cms-stored-cross-site-scripting-via-page-modification - Third Party Advisory |
15 Dec 2025, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.exploit-db.com/exploits/51604 - |
15 Dec 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-15 21:15
Updated : 2025-12-17 15:35
NVD link : CVE-2023-53891
Mitre link : CVE-2023-53891
CVE.ORG link : CVE-2023-53891
JSON object : View
Products Affected
blackcat-cms
- blackcat_cms
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
