Medium severity5.4NVD Advisory· Published Jun 9, 2025· Updated Jul 5, 2026
CVE-2025-46041
CVE-2025-46041
Description
A stored cross-site scripting (XSS) vulnerability in Anchor CMS v0.12.7 allows attackers to inject malicious JavaScript via the page description field in the page creation interface (/admin/pages/add).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3=0.12.7+ 1 more
- (no CPE)range: =0.12.7
- cpe:2.3:a:anchorcms:anchor_cms:0.12.7:*:*:*:*:*:*:*
- Anchor CMS/Anchor CMSdescription
Patches
Vulnerability mechanics
News mentions
0No linked articles in our index yet.