Cross site scripting in Piranha CMS v12.0

CVE-2025-61413
6.1CVSS

A stored cross-site scripting (XSS) vulnerability in the /manager/pages component of Piranha CMS v12.0 allows attackers to execute arbitrary web scripts or HTML via creating a page and injecting a crafted payload into the Markdown blocks bypass of CVE CVE-2024-55341

Piranha CMS v12.0
TitleCross site scripting in
CVE IDCVE-2025-61413
CVSS6.1
Disclosure Date10/23/2025
Statuspublished
CVSS Vectorcvss:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

About Responsible Disclosure

All vulnerabilities I discover are handled through a responsible and coordinated disclosure process. Before any public release, each finding is privately reported to the appropriate vendor, maintainer, or security team to allow sufficient time for verification and remediation. My goal is to ensure that vulnerabilities are addressed effectively and that users remain protected throughout the disclosure lifecycle. I work closely with development teams to validate fixes, provide technical details, and confirm resolution whenever possible. In cases where no fix is issued or the vendor remains unresponsive after multiple contact attempts, the disclosure proceeds in accordance with established coordinated disclosure timelines and ethical reporting standards. CVE identifiers are reserved and published prior to any public disclosure to maintain transparency and integrity in the reporting process. This approach reflects my belief that cybersecurity research should strengthen not disrupt the ecosystem, fostering trust, accountability, and resilience across the global security community.deployments.