Stored XSS Vulnerability in Aimeos GrapesJS CMS Extension
CVE-2025-66468
What is CVE-2025-66468?
The Aimeos GrapesJS CMS extension allows editors to create dynamic content pages using extensible components. However, versions prior to 2021.10.8, 2022.10.8, 2023.10.8, 2024.10.8, and 2025.10.8 are susceptible to a stored XSS vulnerability. If the standard Content Security Policy is disabled, malicious users can inject harmful JavaScript code, potentially compromising the integrity of the web application. This issue has been addressed in subsequent releases, reinforcing security and protecting users from such risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ai-cms-grapesjs >= 2021.04.1, < 2021.10.8 < 2021.04.1, 2021.10.8
ai-cms-grapesjs >= 2022.04.1, < 2022.10.9 < 2022.04.1, 2022.10.9
ai-cms-grapesjs >= 2023.04.1, < 2023.10.15 < 2023.04.1, 2023.10.15
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
