Podcastgenerator
Podcastgenerator Podcast Generator: vulnerabilidades y CVE
Podcastgenerator Podcast Generator tiene 7 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses6
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-47968 | Media (5.1) | 0.19% | — | 15 may 2026 | Podcast Generator 3.1 is vulnerable to persistent cross-site scripting, allowing authenticated attackers to inject malicious scripts by submitting unfiltered JavaScript code in the long_description parameter. Attackers… |
| CVE-2025-70336 | Media (4.8) | 0.55% | — | 28 ene 2026 | A Stored cross-site scripting (XSS) vulnerability in 'Create New Live Item' in PodcastGenerator 3.2.9 allows remote attackers to inject arbitrary script or HTML via the 'TITLE', 'SHORT DESCRIPTION' and 'LONG… |
| CVE-2023-53920 | Media (5.1) | 0.33% | — | 17 dic 2025 | PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the podcast title field accessible through the podcast details interface (podcast_details.php). Malicious JavaScript payloads injected into… |
| CVE-2023-53919 | Media (5.1) | 0.33% | — | 17 dic 2025 | PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the Freebox content field accessible through the theme customization interface (theme_freebox.php). Malicious JavaScript payloads injected… |
| CVE-2023-53918 | Media (5.1) | 0.34% | — | 17 dic 2025 | PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the episode title field accessible through the episodes upload interface (episodes_upload.php). Malicious JavaScript payloads injected into… |
| CVE-2023-53899 | Media (5.1) | 0.57% | — | 16 dic 2025 | PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows attackers to inject XML in the episode upload form. Attackers can manipulate the 'shortdesc' parameter to trigger external… |
| CVE-2018-20121 | Media (6.1) | 1.6% | — | 21 mar 2019 | Podcast Generator 2.7 has stored cross-site scripting (XSS) via the URL addcategory parameter. |