PT-2025-23925 · Rsblog! · Rsblog!

Kamil Szczurowski

+1

·

Published

2025-06-05

·

Updated

2025-06-16

·

CVE-2025-27754

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions RSBlog! component versions 1.11.6 through 1.14.4
Description A stored XSS issue allows authenticated users to inject malicious JavaScript into the plugin's resource. The injected payload is stored by the application and later executed when other users view the affected content.
Recommendations For RSBlog! component versions 1.11.6 through 1.14.4, update to a version that contains a fix for this issue to prevent malicious JavaScript injection. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-27754

Affected Products

Rsblog!