CVE-2023-22427: Ss-Proj Shirasagi

Medium severity, CVSS 4.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Stored cross-site scripting vulnerability in Theme switching function of SHIRASAGI v1.16.2 and earlier versions allows a remote attacker with an administrative privilege to inject an arbitrary script.

Affected products

  • Ss-Proj Shirasagi: up to and including 1.16.2

Published 2023-02-24. Last modified 2026-06-17.