Back to Database
Status published
Low
CVE-2025-53904
The Scratch Channel Has Potential Reflected Cross-Site Scripting (XSS) Vulnerability
Vulnerability Description
The Scratch Channel is a news website that is under development as of time of this writing. The file `/api/admin.js` contains code that could make the website vulnerable to cross-site scripting. No known patches exist as of time of publication.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-53904
Credits & Attribution
No credits recorded in the NVD database.
References
More from The-Scratch-Channel
View All →CVE-2025-59416
The Scratch Channel forks can publish articles
High
7.2
CVE-2025-57805
The Scratch Channel's Publish Articles POST Request Can Upload Articles Without Validation
High
8.7
CVE-2025-55301
The Scratch Channel Allows Username Modification
Medium
6.7
CVE-2025-53903
The Scratch Channel Has Potential Cross-Site Scripting (XSS) Vulnerability
Low
1.3
Affected Vendor
The-Scratch-Channel
View all reports →Affected Software
the-scratch-channel.github.io
Vulnerable Versions:
<= b66a1cae45e05ad8971aecd96c3322520f8a5725
Timeline
Official Publish:
July 16th, 2025
Last Modified:
July 18th, 2025
Added to House:
July 22nd, 2026