Junglewise Threat Intelligence

CVE-2023-32686: PYSEC-2026-1500 - kiwitcms vulnerable to stored XSS via unrestricted files upload

CVE-2023-32686 · Severity: low · CVSS 3.1 · Published 2026-07-07

Technologies: kiwitcms (PyPI). Vendors: PyPI.

Executive brief

kiwitcms vulnerable to stored XSS via unrestricted files upload

Affected products

  • PyPI kiwitcms

Related threats