CVE-2025-12330

Source
https://cve.org/CVERecord?id=CVE-2025-12330
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-12330.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-12330
Published
2025-10-27T22:02:05Z
Modified
2026-08-12T03:51:40Z
Severity
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Willow CMS Add Post add cross site scripting
Details

A security flaw has been discovered in Willow CMS up to 1.4.0. This issue affects some unknown processing of the file /admin/articles/add of the component Add Post Page. The manipulation of the argument title/body results in cross site scripting. The attack may be launched remotely. The exploit has been released to the public and may be exploited.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-79",
        "CWE-94"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/12xxx/CVE-2025-12330.json"
}
References

Affected packages

Git / github.com/matthewdeaves/willow

Affected ranges

Type
GIT
Repo
https://github.com/matthewdeaves/willow
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:matthewdeaves:willow_cms:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.0"
        },
        {
            "last_affected": "1.0"
        },
        {
            "introduced": "1.1"
        },
        {
            "last_affected": "1.1"
        },
        {
            "introduced": "1.2"
        },
        {
            "last_affected": "1.2"
        },
        {
            "introduced": "1.3"
        },
        {
            "last_affected": "1.3"
        },
        {
            "introduced": "1.4.0"
        },
        {
            "last_affected": "1.4.0"
        },
        {
            "introduced": "0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ]
}

Affected versions

1.*
1.0
1.1
1.2
1.3
1.4.0
v1.*
v1.0.0
v1.0.1
v1.0.10
v1.0.11
v1.0.12
v1.0.13
v1.0.14
v1.0.15
v1.0.16
v1.0.17
v1.0.18
v1.0.19
v1.0.2
v1.0.20
v1.0.21
v1.0.22
v1.0.23
v1.0.24
v1.0.25
v1.0.26
v1.0.27
v1.0.28
v1.0.29
v1.0.3
v1.0.30
v1.0.31
v1.0.32
v1.0.33
v1.0.34
v1.0.4
v1.0.5
v1.0.6
v1.0.7
v1.0.8
v1.0.9
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.1.5
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.3.1
v1.3.2
v1.4.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-12330.json"