Cameleon CMS 2.7.4 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts into post titles. Attackers can create posts with embedded SVG scripts that execute when other users mouse over the post title, potentially stealing session cookies and executing arbitrary JavaScript.
History

Fri, 16 Jan 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}


Mon, 12 Jan 2026 19:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:tuzitio:camaleon_cms:2.7.4:*:*:*:*:*:*:*

Fri, 19 Dec 2025 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Tuzitio
Tuzitio camaleon Cms
Vendors & Products Tuzitio
Tuzitio camaleon Cms

Thu, 18 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 18 Dec 2025 20:00:00 +0000

Type Values Removed Values Added
Description Cameleon CMS 2.7.4 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts into post titles. Attackers can create posts with embedded SVG scripts that execute when other users mouse over the post title, potentially stealing session cookies and executing arbitrary JavaScript.
Title Cameleon CMS 2.7.4 Authenticated Persistent Cross-Site Scripting via Post Creation
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-12-18T19:53:33.354Z

Updated: 2026-01-16T19:00:15.747Z

Reserved: 2025-12-16T19:22:09.997Z

Link: CVE-2023-53936

cve-icon Vulnrichment

Updated: 2025-12-18T21:03:51.919Z

cve-icon NVD

Status : Modified

Published: 2025-12-18T20:15:51.843

Modified: 2026-01-16T19:16:13.203

Link: CVE-2023-53936

cve-icon Redhat

No data.