Cross-site Scripting in Agency Dominion Inc.'s Fusion Page Builder Extension - Gallery
CVE-2025-58965

6.5MEDIUM

What is CVE-2025-58965?

A Cross-site Scripting (XSS) vulnerability exists in the Fusion Page Builder Extension - Gallery by Agency Dominion Inc. This issue arises from improper input neutralization during web page generation, potentially allowing attackers to execute arbitrary scripts in the context of an affected user’s session. Affected versions include the extension from the initial release up to 1.7.6, making it crucial for users to apply security patches to mitigate risks associated with this vulnerability.

Affected Version(s)

Fusion Page Builder : Extension &#8211; Gallery <= 1.7.6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Yudha - DJ (Patchstack Alliance)
.
CVE-2025-58965 : Cross-site Scripting in Agency Dominion Inc.'s Fusion Page Builder Extension - Gallery