Products: 1
Vulnerabilities: 3
Known Exploited: 0
0
Critical Level Threats
1
High Level Threats
2
Medium Level Threats
0
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2025-66686
A stored Cross-Site Scripting (XSS) vulnerability exists in Perch CMS version 3.2. An authenticated attacker with administrative privileges can inject malicious JavaScript code into the “Help button url” setting within the admin panel. The injected payload is stored and executed when any authenticated user clicks the Help button, potentially leading to session hijacking, information disclosure, privilege escalation, and unauthorized administrative actions.
Last Modified: Jan 21, 2026
Published: Jan 07, 2026
CVE-2023-53890
Perch CMS 3.2 Stored Cross-Site Scripting via SVG File Upload
Last Modified: Apr 07, 2026
Published: Dec 15, 2025
CVE-2023-53889
Perch CMS 3.2 Remote Code Execution via Unrestricted File Upload
Last Modified: May 12, 2026
Published: Dec 15, 2025
Items Per Page
