CVE-2025-15454

A vulnerability was detected in zhanglun lettura up to 0.1.22. This issue affects some unknown processing of the file src/components/ArticleView/ContentRender.tsx of the component RSS Handler. The manipulation results in cross site scripting. The attack can be executed remotely. This attack is characterized by high complexity. The exploitability is assessed as difficult. The exploit is now public and may be used. The patch is identified as 67213093db9923e828a6e3fd8696a998c85da2d4. It is best practice to apply a patch to resolve this issue.
Configurations

No configuration.

History

05 Jan 2026, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-05 03:15

Updated : 2026-01-08 18:09


NVD link : CVE-2025-15454

Mitre link : CVE-2025-15454

CVE.ORG link : CVE-2025-15454


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')