CVE-2023-53911

Source
https://cve.org/CVERecord?id=CVE-2023-53911
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-53911.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-53911
Published
2025-12-17T22:44:47Z
Modified
2026-08-12T03:51:40Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
Textpattern CMS 4.8.8 Authenticated Stored Cross-Site Scripting via Article Excerpt
Details

Textpattern CMS 4.8.8 contains a stored cross-site scripting vulnerability in the article excerpt field that allows authenticated users to inject malicious scripts. Attackers can insert JavaScript payloads into the excerpt, which will execute when the article is viewed by other users.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/53xxx/CVE-2023-53911.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "4.8.8"
                },
                {
                    "last_affected": "4.8.8"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/textpattern/textpattern

Affected ranges

Type
GIT
Repo
https://github.com/textpattern/textpattern
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:textpattern:textpattern:4.8.8:-:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "4.8.8-NA"
        },
        {
            "last_affected": "4.8.8-NA"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

4.*
4.8.8
4.8.8-NA

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-53911.json"