CVE-2025-60869
Last modified
CVE-2025-60869 is a high-severity vulnerability rated 7.3/10 on the CVSS scale. Publii CMS v0.46.5 (build 17089) allows persistent Cross-Site Scripting (XSS) via unsanitized input in configuration fields such as "Site Description" and "Footer Follow Buttons". An attacker can inject arbitrary JavaScript, which is stored in the project and executed in the browsers of remote visitors viewing the generated static site.. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
Publii CMS v0.46.5 (build 17089) allows persistent Cross-Site Scripting (XSS) via unsanitized input in configuration fields such as "Site Description" and "Footer Follow Buttons". An attacker can inject arbitrary JavaScript, which is stored in the project and executed in the browsers of remote visitors viewing the generated static site.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-60869?
How severe is CVE-2025-60869?
How do I fix CVE-2025-60869?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-60856Reolink Video Doorbell WiFi DB_566128M5MP_W allows root shel…6.8
- CVE-2025-60858Reolink Video Doorbell Wi-Fi DB_566128M5MP_W stores and tran…7.5
- CVE-2025-60859Cross Site Scripting (XSS) vulnerability in Gnuboard 5.6.15 …6.1
- CVE-2025-6086The CSV Me plugin for WordPress is vulnerable to arbitrary f…7.2
- CVE-2025-60865Insecure Permissions vulnerability in avanquest Driver Updat…7.8
- CVE-2025-60868The Alt Redirect 1.6.3 addon for Statamic fails to consisten…6.5
- CVE-2025-6087A Server-Side Request Forgery (SSRF) vulnerability was ident…9.1
- CVE-2025-60876BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and…6.5
- CVE-2025-6088In version 0.7.8 of danny-avila/librechat, improper authoriz…3.1
- CVE-2025-60880An authenticated stored XSS vulnerability exists in the Bagi…8.3
- CVE-2025-60887An issue was discovered in Cista v0.15 and below. Insecure d…5.3
- CVE-2025-60889Insecure deserialization of untrusted input in StellarGroup …9.8
Are you affected by CVE-2025-60869?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
