We found results for “”
CVE-2025-66468
Good to know:
Date: December 2, 2025
The Aimeos GrapesJS CMS extension provides page editor for creating content pages based on extensible components. Prior to 2021.10.8, 2022.10.8, 2023.10.8, 2024.10.8, and 2025.10.8, Javascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. This vulnerability is fixed in 2021.10.8, 2022.10.8, 2023.10.8, 2024.10.8, and 2025.10.8.
Severity Score
Related Resources (5)
Severity Score
Weakness Type (CWE)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79Top Fix
Upgrade Version
Upgrade to version aimeos/ai-cms-grapesjs - 2021.10.8;aimeos/ai-cms-grapesjs - 2022.10.8;aimeos/ai-cms-grapesjs - 2023.10.8;aimeos/ai-cms-grapesjs - 2024.10.8;aimeos/ai-cms-grapesjs - 2025.10.8;https://github.com/aimeos/ai-cms-grapesjs.git - 2021.10.8;https://github.com/aimeos/ai-cms-grapesjs.git - 2022.10.8;https://github.com/aimeos/ai-cms-grapesjs.git - 2023.10.8;https://github.com/aimeos/ai-cms-grapesjs.git - 2024.10.8;https://github.com/aimeos/ai-cms-grapesjs.git - 2025.10.8
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | HIGH |
| Privileges Required (PR): | HIGH |
| User Interaction (UI): | REQUIRED |
| Scope (S): | CHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | HIGH |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


