Cameleon CMS 2.7.4 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts into post titles. Attackers can create posts with embedded SVG scripts that execute when other users mouse over the post title, potentially stealing session cookies and executing arbitrary JavaScript.
References
| Link | Resource |
|---|---|
| https://github.com/owen2345/camaleon-cms | Product |
| https://www.exploit-db.com/exploits/51446 | Exploit Third Party Advisory |
| https://www.vulncheck.com/advisories/cameleon-cms-authenticated-persistent-cross-site-scripting-via-post-creation | Third Party Advisory |
Configurations
History
16 Jan 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.8 |
12 Jan 2026, 19:24
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Tuzitio
Tuzitio camaleon Cms |
|
| References | () https://github.com/owen2345/camaleon-cms - Product | |
| References | () https://www.exploit-db.com/exploits/51446 - Exploit, Third Party Advisory | |
| References | () https://www.vulncheck.com/advisories/cameleon-cms-authenticated-persistent-cross-site-scripting-via-post-creation - Third Party Advisory | |
| CPE | cpe:2.3:a:tuzitio:camaleon_cms:2.7.4:*:*:*:*:*:*:* |
18 Dec 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-18 20:15
Updated : 2026-01-16 19:16
NVD link : CVE-2023-53936
Mitre link : CVE-2023-53936
CVE.ORG link : CVE-2023-53936
JSON object : View
Products Affected
tuzitio
- camaleon_cms
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
