CVE-2023-30758: Pleasanter

Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.

Cross-site scripting vulnerability in Pleasanter 1.3.38.1 and earlier allows a remote authenticated attacker to inject an arbitrary script.

Affected products

  • Pleasanter Pleasanter: before 1.3.38.1 (fixed in 1.3.38.1)

Published 2023-06-01. Last modified 2026-06-17.