PT-2025-31059 · Optimizely · Episerver Cms

F. Beie

+1

·

Published

2025-07-28

·

Updated

2025-07-29

·

CVE-2025-27802

CVSS v3.1
4.8
VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Name of the Vulnerable Software and Affected Versions:

Episerver CMS versions prior to 11.21.4 and prior to 11.37.5

Episerver CMS versions prior to 12.22.1 and prior to 11.37.3

Description:

The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities. This allowed an authenticated attacker to execute malicious JavaScript code in the victim’s browser. RTE properties (text fields) within the "Edit" section of the CMS allowed the input of arbitrary text, enabling the injection of malicious JavaScript code that would execute when a user previews the page. An attacker needed at least the "WebEditor" role to exploit this issue.

Recommendations:

Episerver CMS versions prior to 11.21.4: Update to version 11.21.4 or later.

Episerver CMS versions prior to 11.37.5: Update to version 11.37.5 or later.

Episerver CMS versions prior to 12.22.1: Update to version 12.22.1 or later.

Episerver CMS versions prior to 11.37.3: Update to version 11.37.3 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-27802

Affected Products

Episerver Cms