Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3qcp-9v8c-6jp7 | Piranha CMS vulnerable to stored cross-site scripting (XSS) |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 24 Oct 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored cross-site scripting (XSS) vulnerability in the /manager/pages component of Piranha CMS v12.1 allows attackers to execute arbitrary web scripts or HTML via creating a page and injecting a crafted payload into the Markdown blocks. | A stored cross-site scripting (XSS) vulnerability in the /manager/pages component of Piranha CMS v12.0 allows attackers to execute arbitrary web scripts or HTML via creating a page and injecting a crafted payload into the Markdown blocks. |
Fri, 24 Oct 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dotnetfoundation
Dotnetfoundation piranha Cms |
|
| Vendors & Products |
Dotnetfoundation
Dotnetfoundation piranha Cms |
Thu, 23 Oct 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Thu, 23 Oct 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored cross-site scripting (XSS) vulnerability in the /manager/pages component of Piranha CMS v12.1 allows attackers to execute arbitrary web scripts or HTML via creating a page and injecting a crafted payload into the Markdown blocks. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-10-24T15:16:50.351Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-61413
Updated: 2025-10-23T20:36:11.671Z
Status : Received
Published: 2025-10-23T18:16:23.683
Modified: 2025-10-24T16:27:22.563
Link: CVE-2025-61413
No data.
OpenCVE Enrichment
Updated: 2025-10-24T10:16:50Z
Github GHSA