Description
In PiranhaCMS, versions 7.0.0 to 9.1.1 are vulnerable to stored XSS due to the page title improperly sanitized. By creating a page with a specially crafted page title, a low privileged user can trigger arbitrary JavaScript execution.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update to 9.2.0
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2218 | In PiranhaCMS, versions 7.0.0 to 9.1.1 are vulnerable to stored XSS due to the page title improperly sanitized. By creating a page with a specially crafted page title, a low privileged user can trigger arbitrary JavaScript execution. |
Github GHSA |
GHSA-jvjp-vh27-r9h5 | Cross-site Scripting in PiranhaCMS |
References
History
Wed, 30 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mend
Published:
Updated: 2025-04-30T15:52:58.659Z
Reserved: 2021-01-22T00:00:00.000Z
Link: CVE-2021-25977
Updated: 2024-08-03T20:19:19.780Z
Status : Modified
Published: 2021-10-25T13:15:07.800
Modified: 2024-11-21T05:55:43.080
Link: CVE-2021-25977
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA