In PiranhaCMS, versions 7.0.0 to 9.1.1 are vulnerable to stored XSS due to the page title improperly sanitized. By creating a page with a specially crafted page title, a low privileged user can trigger arbitrary JavaScript execution.

Subscriptions

Vendors Products
Dotnetfoundation Subscribe
Piranha Cms Subscribe

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-2218 In PiranhaCMS, versions 7.0.0 to 9.1.1 are vulnerable to stored XSS due to the page title improperly sanitized. By creating a page with a specially crafted page title, a low privileged user can trigger arbitrary JavaScript execution.
Github GHSA Github GHSA GHSA-jvjp-vh27-r9h5 Cross-site Scripting in PiranhaCMS
Fixes

Solution

Update to 9.2.0


Workaround

No workaround given by the vendor.

History

Wed, 30 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mend

Published:

Updated: 2025-04-30T15:52:58.659Z

Reserved: 2021-01-22T00:00:00.000Z

Link: CVE-2021-25977

cve-icon Vulnrichment

Updated: 2024-08-03T20:19:19.780Z

cve-icon NVD

Status : Modified

Published: 2021-10-25T13:15:07.800

Modified: 2024-11-21T05:55:43.080

Link: CVE-2021-25977

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses