CVE-2024-23168: Xiexe Xsoverlay

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Vulnerability in Xiexe XSOverlay before build 647 allows non-local websites to send the malicious commands to the WebSocket API, resulting in the arbitrary code execution.

Affected products

  • Xiexe Xsoverlay: before 647 (fixed in 647)

Published 2024-08-15. Last modified 2026-06-17.