CVE-2023-32607: Pleasanter

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

Stored cross-site scripting vulnerability in Pleasanter (Community Edition and Enterprise Edition) 1.3.39.2 and earlier versions allows a remote authenticated attacker to inject an arbitrary script.

Affected products

  • Pleasanter Pleasanter: before 1.3.39.2 (fixed in 1.3.39.2)

Published 2023-06-30. Last modified 2026-06-17.