Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 15 May 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 15 May 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Podcast Generator 3.1 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting unfiltered JavaScript code in the long_description parameter. Attackers can inject script tags through episode creation or editing requests to execute arbitrary JavaScript when other users view the episode details. | |
| Title | Podcast Generator 3.1 Persistent Cross-Site Scripting via long_description | |
| First Time appeared |
Podcastgenerator
Podcastgenerator podcast Generator |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:podcastgenerator:podcast_generator:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Podcastgenerator
Podcastgenerator podcast Generator |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-15T20:15:18.959Z
Reserved: 2026-05-15T16:39:50.787Z
Link: CVE-2021-47968
Updated: 2026-05-15T20:15:13.624Z
Status : Received
Published: 2026-05-15T19:16:56.560
Modified: 2026-05-15T19:16:56.560
Link: CVE-2021-47968
No data.
OpenCVE Enrichment
Updated: 2026-05-15T20:30:06Z