Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 20 Jan 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:pyrocms:pyrocms:3.0.1:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Tue, 16 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Dec 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pyrocms
Pyrocms pyrocms |
|
| Vendors & Products |
Pyrocms
Pyrocms pyrocms |
Thu, 11 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PyroCMS v3.0.1 contains a stored cross-site scripting vulnerability in the admin redirects configuration that allows attackers to inject malicious scripts. Attackers can insert a payload in the 'Redirect From' field to execute arbitrary JavaScript when administrators view the redirects page. | |
| Title | PyroCMS v3.0.1 Stored Cross-Site Scripting via Admin Redirects | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-05T12:03:37.077Z
Reserved: 2025-12-11T00:58:28.456Z
Link: CVE-2024-58297
Updated: 2025-12-16T16:22:09.095Z
Status : Analyzed
Published: 2025-12-11T22:15:50.903
Modified: 2026-01-20T18:46:15.510
Link: CVE-2024-58297
No data.
OpenCVE Enrichment
Updated: 2025-12-12T08:49:27Z