CVE-2025-66468

Source
https://cve.org/CVERecord?id=CVE-2025-66468
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66468.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-66468
Aliases
Published
2025-12-02T18:40:44.081Z
Modified
2026-03-14T01:59:48.979382Z
Severity
  • 7.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
Aimeos GrapesJS CMS extension possible stores XSS exploitable by authenticated editors
Details

The Aimeos GrapesJS CMS extension provides page editor for creating content pages based on extensible components. Prior to 2021.10.8, 2022.10.8, 2023.10.8, 2024.10.8, and 2025.10.8, Javascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. This vulnerability is fixed in 2021.10.8, 2022.10.8, 2023.10.8, 2024.10.8, and 2025.10.8.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66468.json"
}
References

Affected packages

Git / github.com/aimeos/ai-cms-grapesjs

Affected ranges

Type
GIT
Repo
https://github.com/aimeos/ai-cms-grapesjs
Events
Database specific
{
    "versions": [
        {
            "introduced": "2021.04.1"
        },
        {
            "fixed": "2021.10.8"
        }
    ]
}
Type
GIT
Repo
https://github.com/aimeos/ai-cms-grapesjs
Events
Database specific
{
    "versions": [
        {
            "introduced": "2022.04.1"
        },
        {
            "fixed": "2022.10.9"
        }
    ]
}
Type
GIT
Repo
https://github.com/aimeos/ai-cms-grapesjs
Events
Database specific
{
    "versions": [
        {
            "introduced": "2023.04.1"
        },
        {
            "fixed": "2023.10.15"
        }
    ]
}
Type
GIT
Repo
https://github.com/aimeos/ai-cms-grapesjs
Events
Database specific
{
    "versions": [
        {
            "introduced": "2024.04.1"
        },
        {
            "fixed": "2024.10.8"
        }
    ]
}
Type
GIT
Repo
https://github.com/aimeos/ai-cms-grapesjs
Events
Database specific
{
    "versions": [
        {
            "introduced": "2025.04.1"
        },
        {
            "fixed": "2025.10.2"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66468.json"