Medium severity6.1OSV Advisory· Published Dec 22, 2025· Updated Jul 5, 2026
CVE-2025-67290
CVE-2025-67290
Description
A stored cross-site scripting (XSS) vulnerability in the Page Settings module of Piranha CMS v12.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Excerpt field.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
PiranhaNuGet | <= 12.0.0 | — |
Affected products
3- Range: v10.0, v10.0-alpha1, v10.0.1, …
- cpe:2.3:a:dotnetfoundation:piranha_cms:12.1:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
4- github.com/vuquyen03/CVE/tree/main/CVE-2025-67290nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-fw48-7qf9-455mghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-67290ghsaADVISORY
- piranha.comghsaWEB
News mentions
0No linked articles in our index yet.