VYPR

Chorus CMS

by Vox Media

CVEs (1)

  • CVE-2025-40730MedJul 28, 2025
    risk 0.31cvss epss 0.00

    HTML injection in Vox Media's Chorus CMS. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL using the 'q' parameter in '/search'. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.