CVE-2025-59117

Source
https://cve.org/CVERecord?id=CVE-2025-59117
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-59117.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-59117
Published
2025-11-18T15:16:34.337Z
Modified
2026-03-13T03:35:26.231626Z
Severity
  • 4.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Windu CMS is vulnerable to multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the page editing endpoint windu/admin/content/pages/edit/. This vulnerability can be exploited by a privileged user and may target users with higher privileges.

Only version 4.1 was tested and confirmed as vulnerable. This issue was fixed in version 4.1 build 2250.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-59117.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "4.1"
            }
        ]
    }
]