
PODCASTGENERATOR STORED XSS PodcastGenerator 3.2.9 has a stored XSS bug. An admin can inject JavaScript that runs on the public Live Stream page. No login needed to trigger it. Read more: https://www.redsecuretech.co.uk/blog/post/podcastgenerator-stored-xss-cve-2025-70336-alert/1495 #PodcastGenerator #StoredXSS #CVE202570336 #WebSecurity #InfoSec https://t.co/KqCJ4pFEbV
Post summary
A stored XSS vulnerability in PodcastGenerator 3.2.9 is disclosed, explaining how an admin can inject JavaScript that executes on a public page without needing to log in, with no PoC, exploit code, patch, or evidence of active exploitation.


