CVE-2023-53891: Blackcat-CMS Blackcat CMS
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Blackcat CMS 1.4 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into page content. Attackers can insert JavaScript payloads in the page modification interface that execute when other users view the compromised page.
Affected products
- Blackcat-CMS Blackcat CMS: version 1.4 only
Published 2025-12-15. Last modified 2026-06-17.