CRITICALMaven →
XWiki Blog Application home page vulnerable to Stored XSS via Post Title
XWiki Blog Application home page vulnerable to Stored XSS via Post Title
Affected packages
- org.xwiki.contrib.blog:application-blog-ui— 9.15 → 9.15.7
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/xwiki-contrib/application-blog/security/advisories/GHSA-h2xq-h7f9-vh6c
- https://nvd.nist.gov/vuln/detail/CVE-2025-66024
- https://github.com/xwiki-contrib/application-blog/commit/cca87f0a0edc2e7e049d46d51f4a4d8f78b714ba
- https://github.com/xwiki-contrib/application-blog/commit/cdcbf2816e9b329e8f006be4391a7ffe80d4bb3f
- https://github.com/xwiki-contrib/application-blog
- https://jira.xwiki.org/browse/BLOG-245
Structured record: https://osv.dev/vulnerability/GHSA-h2xq-h7f9-vh6c
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta