CVE-2023-53906: ProjectSend
Medium severity, CVSS 4.8. EPSS: 0.3% chance of exploitation in the next 30 days.
projectSend r1605 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript through the custom assets configuration page. Attackers can craft a JavaScript payload in the custom assets section that will execute when other users load the affected page, enabling persistent script injection.
Affected products
- ProjectSend ProjectSend: version r1605 only
Published 2025-12-17. Last modified 2026-06-17.