Medium severity6.8NVD Advisory· Published Sep 26, 2025· Updated Jun 17, 2026
CVE-2025-57692
CVE-2025-57692
Description
PiranhaCMS 12.0 allows stored XSS in the Text content block of Standard and Standard Archive Pages via /manager/pages, enabling execution of arbitrary JavaScript in another user s browser.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
PiranhaNuGet | <= 12.0 | — |
Affected products
3- cpe:2.3:a:dotnetfoundation:piranha_cms:12.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
4- github.com/Saconyfx/security-advisories/blob/main/CVE-2025-57692/advisory.mdnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-456v-f425-8mcvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-57692ghsaADVISORY
- github.com/PiranhaCMS/piranha.core/releases/tag/v12.0nvdRelease NotesWEB
News mentions
0No linked articles in our index yet.