CVE-2017-15948: Grabaperch Perch

Medium severity, CVSS 4.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Perch Content Management System 3.0.3 allows unrestricted file upload (with resultant XSS) via the Asset Title field in conjunction with the Select File field. This is exploitable with a Limited Admin account.

Affected products

Published 2017-10-28. Last modified 2026-06-17.