CVE-2025-71165

Typesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the administrative interface within the Tools Status functionality. The path parameter is reflected into the HTML response without proper output encoding in include/admin/Tools/Status.php. An authenticated attacker can supply crafted input containing HTML or JavaScript, resulting in arbitrary script execution in the context of an authenticated user's browser session.
Configurations

Configuration 1 (hide)

cpe:2.3:a:typesettercms:typesetter:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:03

Type Values Removed Values Added
Summary
  • (es) Las versiones de Typesetter CMS hasta la 5.1 inclusive contienen una vulnerabilidad de cross-site scripting (XSS) reflejado en la interfaz administrativa dentro de la funcionalidad de Estado de Herramientas. El parámetro path se refleja en la respuesta HTML sin una codificación de salida adecuada en include/admin/Tools/Status.PHP. Un atacante autenticado puede proporcionar una entrada manipulada que contenga HTML o JavaScript, lo que resulta en la ejecución arbitraria de scripts en el contexto de la sesión del navegador de un usuario autenticado.

21 Jan 2026, 20:46

Type Values Removed Values Added
First Time Typesettercms
Typesettercms typesetter
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CPE cpe:2.3:a:typesettercms:typesetter:*:*:*:*:*:*:*:*
References () https://github.com/Typesetter/Typesetter - () https://github.com/Typesetter/Typesetter - Product
References () https://github.com/Typesetter/Typesetter/issues/709 - () https://github.com/Typesetter/Typesetter/issues/709 - Exploit, Issue Tracking
References () https://www.vulncheck.com/advisories/typesetter-cms-reflected-xss-via-status-php - () https://www.vulncheck.com/advisories/typesetter-cms-reflected-xss-via-status-php - Third Party Advisory

14 Jan 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-14 19:16

Updated : 2026-06-17 10:03


NVD link : CVE-2025-71165

Mitre link : CVE-2025-71165

CVE.ORG link : CVE-2025-71165


JSON object : View

Products Affected

typesettercms

  • typesetter
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')