CVE Feed

    Dashboard / CVE / CVE-2025-66024

    CVE-2025-66024

    The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions starting with 9.15 and prior to 9.15.7 are vulnerable to Stored Cross-Site Scripting (XSS) via the Blog Post Title. The vulnerability arises because the post title is injected directly into the HTML <title> tag without proper escaping. An attacker with permissions to create or edit blog posts can inject malicious JavaScript into the title field. This script will execute in the browser of any user (including administrators) who views the blog post. This leads to potential session hijacking or privilege escalation. The vulnerability has been patched in the blog application version 9.15.7 by adding missing escaping. No known workarounds are available.

    Published:Mar 4, 2026
    Last Modified:Aug 5, 2026
    EPS:Mar 4, 2026
    EPSS Score:0.00353
    CVSS Score:9

    Affected Products

    Vendor
    Xwiki
    Product
    Blog Application
    Vendor
    Xwiki-contrib
    Product
    Application-blog-ui

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High