Medium severity6.1OSV Advisory· Published Dec 22, 2025· Updated Jul 5, 2026
CVE-2025-67291
CVE-2025-67291
Description
A stored cross-site scripting (XSS) vulnerability in the Media module of Piranha CMS v12.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name field.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
PiranhaNuGet | <= 12.0.0 | — |
Affected products
3- Range: v10.0, v10.0-alpha1, v10.0.1, …
- cpe:2.3:a:dotnetfoundation:piranha_cms:12.1:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
4- github.com/vuquyen03/CVE/tree/main/CVE-2025-67291nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-83fp-hh9m-c2jqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-67291ghsaADVISORY
- piranha.comghsaWEB
News mentions
0No linked articles in our index yet.