A Stored cross-site scripting (XSS) vulnerability in 'Create New Live Item' in PodcastGenerator 3.2.9 allows remote attackers to inject arbitrary script or HTML via the 'TITLE', 'SHORT DESCRIPTION' and 'LONG DESCRIPTION' parameters. The saved payload gets executed on 'View All Live Items' and 'Live Stream' pages.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-01-28 16:16
Updated : 2026-01-29 18:16
NVD link : CVE-2025-70336
Mitre link : CVE-2025-70336
CVE.ORG link : CVE-2025-70336
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
