Medium severity4.7NVD Advisory· Published Dec 20, 2024· Updated Jun 17, 2026
CVE-2024-55341
CVE-2024-55341
Description
A stored cross-site scripting (XSS) vulnerability in Piranha CMS 11.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by creating a page via the /manager/pages and then adding a markdown content with the XSS payload.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
PiranhaNuGet | <= 11.1.0 | — |
Affected products
3- cpe:2.3:a:dotnetfoundation:piranha_cms:11.1:*:*:*:*:*:*:*
- Piranha CMS/Piranha CMSdescription
Patches
Vulnerability mechanics
References
3- sec-fortress.github.io/posts/articles/posts/CVE-2024-55341.htmlnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-mmx8-vrfg-hfmqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-55341ghsaADVISORY
News mentions
0No linked articles in our index yet.