Cameleon CMS 2.7.4 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts into post titles. Attackers can create posts with embedded SVG scripts that execute when other users mouse over the post title, potentially stealing session cookies and executing arbitrary JavaScript.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 17 Jan 2026 04:15:00 +0900

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}


Tue, 13 Jan 2026 04:30:00 +0900

Type Values Removed Values Added
CPEs cpe:2.3:a:tuzitio:camaleon_cms:2.7.4:*:*:*:*:*:*:*

Fri, 19 Dec 2025 18:30:00 +0900

Type Values Removed Values Added
First Time appeared Tuzitio
Tuzitio camaleon Cms
Vendors & Products Tuzitio
Tuzitio camaleon Cms

Fri, 19 Dec 2025 07:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 19 Dec 2025 05:00:00 +0900

Type Values Removed Values Added
Description Cameleon CMS 2.7.4 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts into post titles. Attackers can create posts with embedded SVG scripts that execute when other users mouse over the post title, potentially stealing session cookies and executing arbitrary JavaScript.
Title Cameleon CMS 2.7.4 Authenticated Persistent Cross-Site Scripting via Post Creation
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-01-16T19:00:15.747Z

Reserved: 2025-12-16T19:22:09.997Z

Link: CVE-2023-53936

cve-icon Vulnrichment

Updated: 2025-12-18T21:03:51.919Z

cve-icon NVD

Status : Modified

Published: 2025-12-18T20:15:51.843

Modified: 2026-01-16T19:16:13.203

Link: CVE-2023-53936

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-19T18:15:34Z

Weaknesses