Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-38473

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

GazellePW(GazellePosterWall)在提交 86c4bedf727691b5a97af42a4864869d18446449 中存在一个存储型跨站脚本(Stored XSS)漏洞,该漏洞位于字幕删除流程中。远程经过身份认证的用户可以通过精心构造的字幕文件名注入任意 JavaScript 代码。该文件名在上传时被存储,并在后续访问 /subtitles.php?action=delete 时被渲染执行,从而可能导致安全攻击。

AI Predicted 6.1 Difficulty: Easy

Possible ATT&CK Techniques 1 AI

T1189 · Drive-by Compromise
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-38473

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
A Stored XSS vulnerability in the subtitle deletion flow in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote authenticated users to inject arbitrary JavaScript via a crafted subtitle filename, which is stored during upload and later rendered in /subtitles.php?action=delete.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2026-38473

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-38473

登录查看更多情报信息。

Patches & Fixes for CVE-2026-38473 (1)

Exploits & Public PoCs for CVE-2026-38473 (1)

Proof of Concept for CVE-2026-38473 (1)

Other References for CVE-2026-38473 (1)

Same Patch Batch · n/a · 2026-08-25 · 15 CVEs total

CVE-2026-75465 Maccms v10越权漏洞:敏感信息泄露
CVE-2026-75421 aria2<=1.37.0 IOFile::getLine函数栈缓冲区下溢漏洞
CVE-2026-52489 gpac缓冲区溢出漏洞
CVE-2026-52491 libtiff远程代码执行漏洞
CVE-2026-38467 GazellePW标签管理器存在SQL注入漏洞
CVE-2026-38468 GazellePW 任意代码执行漏洞
CVE-2026-51368 TongWeb v.7.0.24代码执行漏洞
CVE-2026-39113 SQLite < 2026-03-11 快照存在缓冲区溢出致DoS漏洞
CVE-2026-38466 GazellePW存储型XSS漏洞
CVE-2026-38465 GazellePW存储型XSS漏洞
CVE-2026-38469 GazellePW存储型XSS漏洞
CVE-2026-38474 GazellePW IP锁管理器存在越权漏洞
CVE-2026-38472 GazellePW存储型XSS漏洞
CVE-2026-38470 GazellePW API越权漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-38473

No comments yet


Leave a comment