Stored XSS Vulnerability in Aimeos GrapesJS CMS Extension
CVE-2025-66468
7.7HIGH
What is CVE-2025-66468?
The Aimeos GrapesJS CMS extension allows editors to create dynamic content pages using extensible components. However, versions prior to 2021.10.8, 2022.10.8, 2023.10.8, 2024.10.8, and 2025.10.8 are susceptible to a stored XSS vulnerability. If the standard Content Security Policy is disabled, malicious users can inject harmful JavaScript code, potentially compromising the integrity of the web application. This issue has been addressed in subsequent releases, reinforcing security and protecting users from such risks.
Affected Version(s)
ai-cms-grapesjs >= 2021.04.1, < 2021.10.8 < 2021.04.1, 2021.10.8
ai-cms-grapesjs >= 2022.04.1, < 2022.10.9 < 2022.04.1, 2022.10.9
ai-cms-grapesjs >= 2023.04.1, < 2023.10.15 < 2023.04.1, 2023.10.15
