🔐 CVE Alert

CVE-2023-53890

UNKNOWN 0.0

Perch CMS 3.2 Stored Cross-Site Scripting via SVG File Upload

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Perch CMS 3.2 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can craft SVG files with script tags that execute when the file is viewed, potentially stealing user session information or performing client-side attacks.

CWE CWE-79
Vendor perch
Product perch
Published Dec 15, 2025
Last Updated Apr 7, 2026
Stay Ahead of the Next One

Get instant alerts for perch perch

Be the first to know when new unknown vulnerabilities affecting perch perch are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Perch / Perch
3.2

References

NVD ↗ CVE.org ↗ EPSS Data ↗
exploit-db.com: https://www.exploit-db.com/exploits/51621 grabaperch.com: https://grabaperch.com/ vulncheck.com: https://www.vulncheck.com/advisories/perch-cms-stored-cross-site-scripting-via-svg-file-upload

Credits

Mirabbas Ağalarov