Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2025-66468

Aimeos GrapesJS CMS extension possible stores XSS exploitable by authenticated editors
Back to all
CVE

CVE-2025-66468

Aimeos GrapesJS CMS extension possible stores XSS exploitable by authenticated editors

The Aimeos GrapesJS CMS extension provides page editor for creating content pages based on extensible components. Prior to 2021.10.8, 2022.10.8, 2023.10.8, 2024.10.8, and 2025.10.8, Javascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. This vulnerability is fixed in 2021.10.8, 2022.10.8, 2023.10.8, 2024.10.8, and 2025.10.8.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
7.6
-
3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66468.json, https://github.com/aimeos/ai-cms-grapesjs/commit/2214f71ac27cdea25f11c8adf6bb5816db47a042, https://github.com/aimeos/ai-cms-grapesjs/security/advisories/GHSA-424m-fj2q-g7vg, https://nvd.nist.gov/vuln/detail/CVE-2025-66468

Severity

7.6

CVSS Score
0
10

Basic Information

Ecosystem
Base CVSS
7.6
EPSS Probability
0.00045%
EPSS Percentile
0.13594%
Introduced Version
a251ee69b6f899ee6c01dc4b3bf96c523b7328f4,01a4746a137219ab21b243d7516848d991bf2989,2f70f726749c05002144a1c4aec8bec06b19a1e2,3d63a3aa5b6fb364785c180d8737cff9f5f6a693,d8f2d1f6960a2cc87509087183a0c078652ba7a5
Fix Available
7e6d3085b3d2ad29843aadf9536c9346b2e4186c,43097d4d277f455be0d197b14abc4eefdc41870d,09d1424a2914bba82e093423059a6719f879428d,28b285538ab39716f8e2973b50f118e950a71c72,de46f88148e1993975251cd3bbc3859df8f10e12

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading