CouchCMS 2.2.1 contains a cross-site scripting vulnerability that allows authenticated attackers to execute arbitrary JavaScript by uploading malicious SVG files through the file upload functionality. Attackers can upload SVG files containing embedded script tags to the browse.php endpoint, which are then executed in users' browsers when the files are accessed or previewed.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-05-16 16:16
Updated : 2026-06-17 04:18
NVD link : CVE-2021-47955
Mitre link : CVE-2021-47955
CVE.ORG link : CVE-2021-47955
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
