YouPHPTube <= 7.8 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the redirectUri parameter in the signup page. Attackers can craft special signup URLs with embedded script tags to execute arbitrary JavaScript in victims' browsers when they access the signup page.
History

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:youphptube:youphptube:*:*:*:*:*:*:*:*

Wed, 14 Jan 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 14 Jan 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Youphptube
Youphptube youphptube
Vendors & Products Youphptube
Youphptube youphptube

Tue, 13 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description YouPHPTube <= 7.8 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the redirectUri parameter in the signup page. Attackers can craft special signup URLs with embedded script tags to execute arbitrary JavaScript in victims' browsers when they access the signup page.
Title YouPHPTube <= 7.8 - Cross-Site Scripting
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-01-13T22:56:03.555Z

Updated: 2026-01-14T15:13:28.351Z

Reserved: 2026-01-10T13:48:08.268Z

Link: CVE-2021-47750

cve-icon Vulnrichment

Updated: 2026-01-14T15:13:25.906Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-13T23:15:49.097

Modified: 2026-01-22T20:27:30.770

Link: CVE-2021-47750

cve-icon Redhat

No data.