A
Stored cross-site scripting (XSS) vulnerability in 'Create New Live Item' in PodcastGenerator 3.2.9 allows remote attackers to inject arbitrary script or HTML via the 'TITLE', 'SHORT DESCRIPTION' and 'LONG DESCRIPTION' parameters. The saved payload gets executed on 'View All Live Items' and 'Live Stream' pages.
References
| Link | Resource |
|---|---|
| https://github.com/PodcastGenerator/PodcastGenerator | Product |
| https://github.com/aryasahil96-manu/CVE-Disclosures/blob/main/CVE-2025-70336 | Third Party Advisory |
Configurations
History
09 Feb 2026, 18:50
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/PodcastGenerator/PodcastGenerator - Product | |
| References | () https://github.com/aryasahil96-manu/CVE-Disclosures/blob/main/CVE-2025-70336 - Third Party Advisory | |
| CPE | cpe:2.3:a:podcastgenerator:podcast_generator:3.2.9:*:*:*:*:*:*:* | |
| First Time |
Podcastgenerator
Podcastgenerator podcast Generator |
29 Jan 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-79 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.8 |
28 Jan 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-28 16:16
Updated : 2026-02-09 18:50
NVD link : CVE-2025-70336
Mitre link : CVE-2025-70336
CVE.ORG link : CVE-2025-70336
JSON object : View
Products Affected
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')