PT-2025-43196 · Crocoblock · Jetblog

Stealthcopter

·

Published

2025-10-22

·

Updated

2025-11-18

·

CVE-2025-49932

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions CrocoBlock JetBlog versions through 2.4.4.1
Description A flaw exists in CrocoBlock JetBlog that allows for Stored Cross-site Scripting (XSS). This issue arises from improper neutralization of input during web page generation. An attacker could potentially inject malicious scripts into web pages viewed by other users. The vulnerable component is jet-blog.
Recommendations Update CrocoBlock JetBlog to a version later than 2.4.4.1.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-49932

Affected Products

Jetblog