A Stored cross-site scripting (XSS) vulnerability in 'Create New Live Item' in PodcastGenerator 3.2.9 allows remote attackers to inject arbitrary script or HTML via the 'TITLE', 'SHORT DESCRIPTION' and 'LONG DESCRIPTION' parameters. The saved payload gets executed on 'View All Live Items' and 'Live Stream' pages.
History

Wed, 28 Jan 2026 15:45:00 +0000

Type Values Removed Values Added
Description A Stored cross-site scripting (XSS) vulnerability in 'Create New Live Item' in PodcastGenerator 3.2.9 allows remote attackers to inject arbitrary script or HTML via the 'TITLE', 'SHORT DESCRIPTION' and 'LONG DESCRIPTION' parameters. The saved payload gets executed on 'View All Live Items' and 'Live Stream' pages.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-01-28T15:22:40.902Z

Reserved: 2026-01-09T00:00:00.000Z

Link: CVE-2025-70336

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-28T16:16:15.717

Modified: 2026-01-28T16:16:15.717

Link: CVE-2025-70336

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.