CVE-2025-66468
Plain English Summary
AI-powered analysis for quick understanding
This vulnerability allows an attacker to inject malicious JavaScript code into the content pages of the Aimeos GrapesJS CMS, potentially leading to a stored cross-site scripting (XSS) attack. This can happen if the site's standard security feature, the Content Security Policy, is turned off and the attacker has access as an editor.
Technical Description
The Aimeos GrapesJS CMS extension provides page editor for creating content pages based on extensible components. Prior to 2021.10.8, 2022.10.8, 2023.10.8, 2024.10.8, and 2025.10.8, Javascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. This vulnerability is fixed in 2021.10.8, 2022.10.8, 2023.10.8, 2024.10.8, and 2025.10.8.
CVSS Vector Analysis
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Quick Information
Published
Dec 2, 2025
4 months ago
Last Modified
Mar 10, 2026
28 days ago
Vendor
aimeos
Product
grapesjs cms