🔐 CVE Alert

CVE-2023-53906

MEDIUM 4.8

ProjectSend r1605 Stored Cross-Site Scripting via Custom Assets Page

CVSS Score
4.8
EPSS Score
0.0%
EPSS Percentile
0th

projectSend r1605 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript through the custom assets configuration page. Attackers can craft a JavaScript payload in the custom assets section that will execute when other users load the affected page, enabling persistent script injection.

CWE CWE-79
Vendor projectsend
Product projectsend
Published Dec 17, 2025
Last Updated Apr 7, 2026
Stay Ahead of the Next One

Get instant alerts for projectsend projectsend

Be the first to know when new medium vulnerabilities affecting projectsend projectsend are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

projectSend / projectSend
r1605

References

NVD ↗ CVE.org ↗ EPSS Data ↗
exploit-db.com: https://www.exploit-db.com/exploits/51518 projectsend.org: https://www.projectsend.org/ vulncheck.com: https://www.vulncheck.com/advisories/projectsend-stored-cross-site-scripting-via-custom-assets-page

Credits

Mirabbas Ağalarov