---
id: CVE-2024-58285
title: >-
  Chyrp 2.5.2 contains a stored cross-site scripting vulnerability that allows
  authenticated users to inject malicious scripts into post titles
summary: >-
  Chyrp 2.5.2 contains a stored cross-site scripting vulnerability that allows
  authenticated users to inject malicious scripts into post titles. Attackers
  can craft payloads in the title field that will execute when the post is
  viewed by o…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: chyrp
product: chyrp
affected:
  - chyrp = 2.5.2
published: '2025-12-10'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T21:10:00.130'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-58285'
references:
  - url: 'https://github.com/chyrp/'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/chyrp/chyrp/archive/refs/tags/v2.5.2.zip'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/52013'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/chyrp-stored-cross-site-scripting-vulnerability-via-post-title
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/52013'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.0026
epssPercentile: 0.15852
ingestedAt: '2026-09-26T21:38:01.499Z'
---

## Overview

Chyrp 2.5.2 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into post titles. Attackers can craft payloads in the title field that will execute when the post is viewed by other users, potentially stealing session cookies or performing client-side attacks.

## Affected

- `chyrp = 2.5.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
