Stored XSS Vulnerability in Optimizely Episerver Content Management System
CVE-2025-27802
What is CVE-2025-27802?
The Optimizely Episerver Content Management System (CMS) is susceptible to multiple stored cross-site scripting (XSS) vulnerabilities. These weaknesses can be exploited by authenticated users, specifically those with 'WebEditor' roles, to inject arbitrary JavaScript code into text fields within the CMS. Once embedded, this malicious code executes in the browsers of users accessing the previewed pages, potentially leading to unauthorized access and data compromise.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Episerver Content Management System (CMS) 11.x < 11.21.4
Episerver Content Management System (CMS) 12.x < 12.22.1
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
