CVE-2023-53906: ProjectSend

Medium severity, CVSS 4.8. EPSS: 0.3% chance of exploitation in the next 30 days.

projectSend r1605 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript through the custom assets configuration page. Attackers can craft a JavaScript payload in the custom assets section that will execute when other users load the affected page, enabling persistent script injection.

Affected products

Published 2025-12-17. Last modified 2026-06-17.