Optimizely · Episerver.Cms.Core · CVE-2025-27800
**Name of the Vulnerable Software and Affected Versions**
Episerver CMS versions prior to 11.21.4 and EPiServer.CMS.UI versions prior to 11.37.5
Episerver CMS versions prior to 12.22.1 and EPiServer.CMS.UI versions prior to 11.37.3
**Description**
The Episerver Content Management System (CMS) by Optimizely is affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities. An authenticated attacker can execute malicious JavaScript code in the victim’s browser. The Admin dashboard allows adding gadgets, including a "Notes" gadget. An attacker with appropriate access rights can insert malicious JavaScript code into these notes, which will be executed when a victim views the dashboard.
**Recommendations**
Update EPiServer.CMS.Core to version 11.21.4 or later.
Update EPiServer.CMS.UI to version 11.37.5 or later.
Update EPiServer.CMS.Core to version 12.22.1 or later.
Update EPiServer.CMS.UI to version 11.37.3 or later.