PT-2025-39731 · Westboy · Cicadascms

Xmttz

·

Published

2025-09-27

·

Updated

2025-09-27

·

CVE-2025-11068

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions westboy CicadasCMS version 1.0
Description A cross site scripting issue exists in an unknown functionality of the file /system/cms/category/save. The manipulation of the categoryName argument can lead to the execution of remote scripts. The exploit for this issue has been publicly released.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-11068

Affected Products

Cicadascms