VendorsPodcast Generatorpodcast_generator3.2.9
Vulnerabilities

Podcast Generator Podcast Generator 3.2.9

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2023-53899
PodcastGenerator 3.2.9 Blind Server-Side Request Forgery via XML Injection
Published 2025-12-16 · Analyzed
9.8EPSS 0.006
CVE-2023-53918
PodcastGenerator Stored Cross-Site Scripting via Episode Title Field
Published 2025-12-17 · Modified
6.1EPSS 0.003
CVE-2023-53919
PodcastGenerator Stored Cross-Site Scripting via Freebox Content Field
Published 2025-12-17 · Modified
5.4EPSS 0.003
CVE-2023-53920
PodcastGenerator Stored Cross-Site Scripting via Podcast Title Field
Published 2025-12-17 · Modified
5.4EPSS 0.003
CVE-2025-70336
A Stored cross-site scripting (XSS) vulnerability in 'Create New Live Item' in PodcastGenerator 3.2.9 allows remote attackers to inject arbitrary script or HTML via the 'TITLE', 'SHORT DESCRIPTION' and 'LONG DESCRIPTION' parameters. The saved payload gets executed on 'View All Live Items' and 'Live Stream' pages.
Published 2026-01-28 · Analyzed
4.81 PoCEPSS 0.006