Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-15118 | The does not sanitise and escape some parameters when outputting them back in a page, allowing unauthenticated users the ability to perform stored Cross-Site Scripting attacks. |
Thu, 15 Jan 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Italia
Italia design Comuni Italia |
|
| CPEs | cpe:2.3:a:italia:design_comuni_italia:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Developers.italia
Developers.italia design Comuni Wordpress Theme |
Italia
Italia design Comuni Italia |
Tue, 13 Jan 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Developers.italia
Developers.italia design Comuni Wordpress Theme |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:developers.italia:design_comuni_wordpress_theme:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Developers.italia
Developers.italia design Comuni Wordpress Theme |
Tue, 25 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 25 Mar 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The does not sanitise and escape some parameters when outputting them back in a page, allowing unauthenticated users the ability to perform stored Cross-Site Scripting attacks. | |
| Title | Design Comuni Italia < 1.1.2 - Unauthenticated Stored XSS | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-03-25T13:36:41.604Z
Reserved: 2025-02-28T19:59:48.968Z
Link: CVE-2025-1798
Updated: 2025-03-25T13:36:37.456Z
Status : Analyzed
Published: 2025-03-25T06:15:40.480
Modified: 2026-01-15T19:49:30.560
Link: CVE-2025-1798
No data.
OpenCVE Enrichment
No data.
EUVD