CVE-2025-70336Disclosure(podcastgenerator / podcast_generator)

LOWCVSS 4.8 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A Stored cross-site scripting (XSS) vulnerability in 'Create New Live Item' in PodcastGenerator 3.2.9 allows remote attackers to inject arbitrary script or HTML via the 'TITLE', 'SHORT DESCRIPTION' and 'LONG DESCRIPTION' parameters. The saved payload gets executed on 'View All Live Items' and 'Live Stream' pages.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • podcast_generator

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-01-28); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
podcast_generator

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-01-28: 2Mentions · 2026-09-12: 1PoC Mentioned / Linked · 2026-01-28: 1Technical Details · 2026-01-28: 2Technical Details · 2026-09-12: 101-2809-12
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-01-282
Disclosure2
2026-09-121
Disclosure1
Full discourse3 posts
  • Red Secure Tech Ltd.@redsecuretech
    Disclosure

    PODCASTGENERATOR STORED XSS PodcastGenerator 3.2.9 has a stored XSS bug. An admin can inject JavaScript that runs on the public Live Stream page. No login needed to trigger it. Read more: https://www.redsecuretech.co.uk/blog/post/podcastgenerator-stored-xss-cve-2025-70336-alert/1495 #PodcastGenerator #StoredXSS #CVE202570336 #WebSecurity #InfoSec https://t.co/KqCJ4pFEbV

    Post summary

    A stored XSS vulnerability in PodcastGenerator 3.2.9 is disclosed, explaining how an admin can inject JavaScript that executes on a public page without needing to log in, with no PoC, exploit code, patch, or evidence of active exploitation.

    0102052
    87 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-70336 A Stored cross-site scripting (XSS) vulnerability in 'Create New Live Item' in PodcastGenerator 3.2.9 allows remote attackers to inject arbitrary script or HTML via t… https://www.cve.org/CVERecord?id=CVE-2025-70336

    Post summary

    The post announces a new stored XSS vulnerability in PodcastGenerator 3.2.9, providing basic technical details but no exploitation or mitigation information.

    10011197
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-70336 Stored XSS in PodcastGenerator 3.2.9 via Live Item Creati... https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-70336 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet announces a stored XSS vulnerability (CVE‑2025‑70336) in PodcastGenerator 3.2.9, referencing a Vulmon page that likely hosts a PoC, but no exploitation or patch information is provided.

    0001046
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppodcastgeneratorpodcast_generator3.2.9--

Explore more