Orangescrum 1.8.0 Cross-Site Scripting via Authenticated Endpoints Severity Medium Date December 23, 2025 Affecting Orangescrum 1.8.0 Vulnerability CVE-2021-47716 CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVSS Score 6.1 CVSS:3.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/Si:L/SA:N References ExploitDB-50554 Official Orangescrum Product Homepage Credit Hubert Wojciechowski Description Orangescrum 1.8.0 contains multiple cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts through various input parameters. Attackers can exploit parameters like 'projid', 'CS_message', and 'name' to execute arbitrary JavaScript code in victim's browsers by submitting crafted payloads through application endpoints.