VYPR
Unrated severityNVD Advisory· Published Dec 11, 2025· Updated Mar 5, 2026

PyroCMS v3.0.1 Stored Cross-Site Scripting via Admin Redirects

CVE-2024-58297

Description

PyroCMS v3.0.1 contains a stored cross-site scripting vulnerability in the admin redirects configuration that allows attackers to inject malicious scripts. Attackers can insert a payload in the 'Redirect From' field to execute arbitrary JavaScript when administrators view the redirects page.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.