Stored XSS Vulnerability in KUNO CMS Blog Application
CVE-2025-61681
What is CVE-2025-61681?
KUNO CMS, a full-stack blog application, suffers from vulnerabilities related to improper validation in its file upload functionality. Versions up to 1.3.13 are particularly at risk, as they allow malicious SVG files to be uploaded disguised as images. The system only verifies file types using Content-Type headers and does not perform thorough file content analysis or implement an extension whitelist, paving the way for attacks. When users access resources linked to these uploads, harmful JavaScript executes in their browsers, leading to potential data breaches and security risks. To mitigate this issue, users are advised to upgrade to version 1.3.14, where the vulnerability has been addressed.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
kuno < 1.3.14
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
