CVE Feed

    Dashboard / CVE / CVE-2025-6050

    CVE-2025-6050

    Mezzanine CMS, in versions prior to 6.1.1, contains a Stored Cross-Site Scripting (XSS) vulnerability in the admin interface. The vulnerability exists in the "displayable_links_js" function, which fails to properly sanitize blog post titles before including them in JSON responses served via "/admin/displayable_links.js". An authenticated admin user can create a blog post with a malicious JavaScript payload in the title field, then trick another admin user into clicking a direct link to the "/admin/displayable_links.js" endpoint, causing the malicious script to execute in their browser.

    Published:Jun 17, 2025
    Last Modified:Jul 30, 2025
    EPS:Jun 17, 2025
    EPSS Score:0.00043
    CVSS Score:4.8

    Affected Products

    Vendor
    Jupo
    Product
    Mezzanine

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2025-6050 — Jupo (Medium 4.8) | CVE-DB