Grabaperch develops Perch, a content management system whose vulnerability profile centers on web-application input handling, with recurrent weaknesses in cross-site scripting and unrestricted file uploads. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Grabaperch over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-53889HIGH Perch CMS 3.2 contains a remote code execution vulnerability that allows authenticated administrators to upload arbitrary PHP files through the assets management interface. Attacke | Dec 15, 2025 | 7.2 | 24 | NO | NO |
CVE-2025-66686MEDIUM A stored Cross-Site Scripting (XSS) vulnerability exists in Perch CMS version 3.2. An authenticated attacker with administrative privileges can inject malicious JavaScript code int | Jan 7, 2026 | 6.1 | 19 | NO | NO |
CVE-2023-53890MEDIUM Perch CMS 3.2 contains a stored cross-site scripting vulnerability that allows authenticated users to upload malicious SVG files with embedded JavaScript. Attackers can craft SVG f | Dec 15, 2025 | 5.4 | 18 | NO | NO |
CVE-2017-15948MEDIUM Perch Content Management System 3.0.3 allows unrestricted file upload (with resultant XSS) via the Asset Title field in conjunction with the Select File field. This is exploitable | Oct 28, 2017 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Grabaperch.
Media articles that mention a CVE ID that affects a product developed by Grabaperch — matched by CVE ID, not by vendor name.