CVE-2025-66468

The Aimeos GrapesJS CMS extension provides page editor for creating content pages based on extensible components. Prior to 2021.10.8, 2022.10.8, 2023.10.8, 2024.10.8, and 2025.10.8, Javascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. This vulnerability is fixed in 2021.10.8, 2022.10.8, 2023.10.8, 2024.10.8, and 2025.10.8.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:aimeos:grapesjs_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:aimeos:grapesjs_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:aimeos:grapesjs_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:aimeos:grapesjs_cms:*:*:*:*:*:*:*:*
cpe:2.3:a:aimeos:grapesjs_cms:*:*:*:*:*:*:*:*

History

10 Mar 2026, 19:38

Type Values Removed Values Added
References () https://github.com/aimeos/ai-cms-grapesjs/commit/2214f71ac27cdea25f11c8adf6bb5816db47a042 - () https://github.com/aimeos/ai-cms-grapesjs/commit/2214f71ac27cdea25f11c8adf6bb5816db47a042 - Patch
References () https://github.com/aimeos/ai-cms-grapesjs/security/advisories/GHSA-424m-fj2q-g7vg - () https://github.com/aimeos/ai-cms-grapesjs/security/advisories/GHSA-424m-fj2q-g7vg - Vendor Advisory
CPE cpe:2.3:a:aimeos:grapesjs_cms:*:*:*:*:*:*:*:*
First Time Aimeos grapesjs Cms
Aimeos

02 Dec 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-02 19:15

Updated : 2026-03-10 19:38


NVD link : CVE-2025-66468

Mitre link : CVE-2025-66468

CVE.ORG link : CVE-2025-66468


JSON object : View

Products Affected

aimeos

  • grapesjs_cms
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')