PT-2025-52684 · Unknown · Piranha Cms
Vuquyen03
·
Published
2025-12-22
·
Updated
2026-01-02
·
CVE-2025-67290
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Piranha CMS version 12.1
Description
A stored cross-site scripting (XSS) issue exists in the Page Settings module. This allows attackers to execute arbitrary web scripts or HTML by injecting a crafted payload into the Excerpt field.
Recommendations
Update Piranha CMS to a newer version that contains a fix for this vulnerability. As a temporary workaround, sanitize all input to the Excerpt field in the Page Settings module to prevent the injection of malicious scripts.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Piranha Cms