CVE-2025-1798

The does not sanitise and escape some parameters when outputting them back in a page, allowing unauthenticated users the ability to perform stored Cross-Site Scripting attacks.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:italia:design_comuni_italia:*:*:*:*:*:wordpress:*:*

History

15 Jan 2026, 19:49

Type Values Removed Values Added
First Time Italia
Italia design Comuni Italia
CPE cpe:2.3:a:developers.italia:design_comuni_wordpress_theme:*:*:*:*:*:wordpress:*:* cpe:2.3:a:italia:design_comuni_italia:*:*:*:*:*:wordpress:*:*

13 Jan 2026, 16:30

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/c5c30191-857c-419c-9096-d1fe14d34eaa/ - () https://wpscan.com/vulnerability/c5c30191-857c-419c-9096-d1fe14d34eaa/ - Exploit, Third Party Advisory
CWE CWE-352
First Time Developers.italia
Developers.italia design Comuni Wordpress Theme
CPE cpe:2.3:a:developers.italia:design_comuni_wordpress_theme:*:*:*:*:*:wordpress:*:*

27 Mar 2025, 16:45

Type Values Removed Values Added
Summary
  • (es) No depura ni escapa algunos parámetros al mostrarlos en una página, lo que permite que usuarios no autenticados tengan la capacidad de realizar ataques de cross site scripting almacenado.

25 Mar 2025, 14:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

25 Mar 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-25 06:15

Updated : 2026-01-15 19:49


NVD link : CVE-2025-1798

Mitre link : CVE-2025-1798

CVE.ORG link : CVE-2025-1798


JSON object : View

Products Affected

italia

  • design_comuni_italia
CWE
CWE-352

Cross-Site Request Forgery (CSRF)