CVE-2023-53939 MEDIUM

CVE-2023-53939: TinyWebGallery v2.5 Stored Cross-Site Scripting via Folder Name Parameter

Vendor Tinywebgallery
Product TinyWebGallery
Weakness CWE-79 · XSS
Published December 18, 2025
Last update April 7, 2026

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

What the vulnerability does

01Description

TinyWebGallery v2.5 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the folder name parameter. Attackers can edit album folder names with script tags to execute arbitrary JavaScript when other users view the affected gallery pages.

Key dates

02Disclosure timeline

December 18, 2025 CVE published
April 7, 2026 Record updated