Piranha CMS vulnerable to stored cross-site scripting (XSS)
Moderate severity GitHub Reviewed Published Oct 23, 2025 to the GitHub Advisory Database • Updated Oct 27, 2025
Description
Published by the National Vulnerability DatabaseOct 23, 2025
Published to the GitHub Advisory Database Oct 23, 2025
Reviewed Oct 23, 2025
Last updated Oct 27, 2025
A stored cross-site scripting (XSS) vulnerability in the /manager/pages component of Piranha CMS v12.0 allows attackers to execute arbitrary web scripts or HTML via creating a page and injecting a crafted payload into the Markdown blocks.
References