Stored XSS Vulnerability in Aimeos GrapesJS CMS Extension
CVE-2025-66468

7.7HIGH

Key Information:

Vendor

Aimeos

Vendor
CVE Published:
2 December 2025

What is CVE-2025-66468?

The Aimeos GrapesJS CMS extension allows editors to create dynamic content pages using extensible components. However, versions prior to 2021.10.8, 2022.10.8, 2023.10.8, 2024.10.8, and 2025.10.8 are susceptible to a stored XSS vulnerability. If the standard Content Security Policy is disabled, malicious users can inject harmful JavaScript code, potentially compromising the integrity of the web application. This issue has been addressed in subsequent releases, reinforcing security and protecting users from such risks.

Affected Version(s)

ai-cms-grapesjs >= 2021.04.1, < 2021.10.8 < 2021.04.1, 2021.10.8

ai-cms-grapesjs >= 2022.04.1, < 2022.10.9 < 2022.04.1, 2022.10.9

ai-cms-grapesjs >= 2023.04.1, < 2023.10.15 < 2023.04.1, 2023.10.15

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.