The Aimeos GrapesJS CMS extension provides page editor for creating content pages based on extensible components. Prior to 2021.10.8, 2022.10.8, 2023.10.8, 2024.10.8, and 2025.10.8, Javascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. This vulnerability is fixed in 2021.10.8, 2022.10.8, 2023.10.8, 2024.10.8, and 2025.10.8.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-424m-fj2q-g7vg Aimeos GrapesJS CMS extension has possible stored XSS that's exploitable by authenticated editors
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 04 Dec 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Aimeos
Aimeos ai-cms-grapesjs
Vendors & Products Aimeos
Aimeos ai-cms-grapesjs

Tue, 02 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 02 Dec 2025 19:00:00 +0000

Type Values Removed Values Added
Description The Aimeos GrapesJS CMS extension provides page editor for creating content pages based on extensible components. Prior to 2021.10.8, 2022.10.8, 2023.10.8, 2024.10.8, and 2025.10.8, Javascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. This vulnerability is fixed in 2021.10.8, 2022.10.8, 2023.10.8, 2024.10.8, and 2025.10.8.
Title Aimeos GrapesJS CMS extension possible stores XSS exploitable by authenticated editors
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-12-02T19:25:50.350Z

Reserved: 2025-12-02T15:43:16.585Z

Link: CVE-2025-66468

cve-icon Vulnrichment

Updated: 2025-12-02T19:25:46.371Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-02T19:15:53.310

Modified: 2025-12-04T17:15:25.860

Link: CVE-2025-66468

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-04T16:44:42Z

Weaknesses