WebsiteBaker 2.13.3 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG files with script tags that execute when the file is viewed, enabling persistent cross-site scripting attacks.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 25 Dec 2025 03:00:00 +0900

Type Values Removed Values Added
CPEs cpe:2.3:a:websitebaker:websitebaker:2.13.3:*:*:*:*:*:*:*

Wed, 17 Dec 2025 07:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 17 Dec 2025 06:00:00 +0900

Type Values Removed Values Added
First Time appeared Websitebaker
Websitebaker websitebaker
Vendors & Products Websitebaker
Websitebaker websitebaker

Wed, 17 Dec 2025 02:30:00 +0900


Wed, 17 Dec 2025 02:15:00 +0900

Type Values Removed Values Added
Description WebsiteBaker 2.13.3 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG files with script tags that execute when the file is viewed, enabling persistent cross-site scripting attacks.
Title WebsiteBaker 2.13.3 Stored Cross-Site Scripting via SVG File Upload
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-12-16T21:44:03.498Z

Reserved: 2025-12-16T00:10:40.314Z

Link: CVE-2023-53903

cve-icon Vulnrichment

Updated: 2025-12-16T21:44:00.323Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-16T17:16:02.700

Modified: 2025-12-24T17:54:34.197

Link: CVE-2023-53903

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-17T05:45:05Z

Weaknesses