CVE-2025-13182
MEDIUMCVSS 4.8/10EPSS 0.22%
Last modified
CVE-2025-13182 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. A vulnerability was identified in pojoin h3blog 1.0. The impacted element is an unknown function of the file /admin/cms/category/addtitle. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
A vulnerability was identified in pojoin h3blog 1.0. The impacted element is an unknown function of the file /admin/cms/category/addtitle. The manipulation of the argument Title leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and might be used.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| H3blog | H3blog | 1.0.0 |
References
- https://github.com/caigo8/CVE-md/blob/main/h3blog/xss3.mdExploit, Third Party Advisory
- https://github.com/caigo8/CVE-md/blob/main/h3blog/xss3.md#vulnerability-reproductionExploit, Third Party Advisory
- https://vuldb.com/?ctiid.332472Permissions Required
- https://vuldb.com/?id.332472Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.685520Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-13182?
A vulnerability was identified in pojoin h3blog 1.0. The impacted element is an unknown function of the file /admin/cms/category/addtitle. The manipulation of the argument Title leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and might be used.
How severe is CVE-2025-13182?
CVE-2025-13182 has a CVSS score of 4.8/10 (MEDIUM severity). The EPSS model estimates a 0.22% probability of exploitation in the next 30 days.
How do I fix CVE-2025-13182?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-13177A vulnerability was detected in Bdtask/CodeCanyon SalesERP u…8.8
- CVE-2025-13178A flaw has been found in Bdtask/CodeCanyon SalesERP up to 20…5.4
- CVE-2025-13179A vulnerability has been found in Bdtask/CodeCanyon Wholesal…6.5
- CVE-2025-1318Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-13180A vulnerability was found in Bdtask/CodeCanyon Wholesale Inv…5.4
- CVE-2025-13181A vulnerability was determined in pojoin h3blog 1.0. The aff…4.8
- CVE-2025-13183Improper Neutralization of Input During Web Page Generation …7.3
- CVE-2025-13184Unauthenticated Telnet enablement via cstecgi.cgi (auth bypa…9.8
- CVE-2025-13185A security flaw has been discovered in Bdtask/CodeCanyon New…7.2
- CVE-2025-13186A weakness has been identified in Bdtask/CodeCanyon Isshue M…5.4
- CVE-2025-13187A security vulnerability has been detected in Intelbras ICIP…7.5
- CVE-2025-13188A vulnerability was detected in D-Link DIR-816L 2_06_b09_bet…9.8
Are you affected by CVE-2025-13182?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
