Stored Cross-Site Scripting in Anchor CMS by Anchor
CVE-2025-46041

5.4MEDIUM

Key Information:

Vendor

Anchor

Vendor
CVE Published:
9 June 2025

What is CVE-2025-46041?

A stored cross-site scripting (XSS) vulnerability exists in Anchor CMS version 0.12.7, which allows attackers to exploit the page description field in the page creation interface. Through this, they can inject and execute malicious JavaScript payloads on victim's browsers, potentially leading to unauthorized actions and data theft. It is crucial for users to implement patches and sanitize user inputs to mitigate the risk of exploitation.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.