Description
A Cross Site Scripting (XSS) vulnerability exists in Decap CMS thru 3.8.3. Input fields such as body, tags, title, and description are not properly sanitized before being rendered in the content preview pane. This enables an attacker to inject arbitrary JavaScript which executes whenever a user views the preview panel. The vulnerability affects multiple input vectors and does not require user interaction beyond viewing the affected content.
INFO
Published Date :
2025-09-10T00:00:00.000Z
Last Modified :
2025-09-11T18:26:06.358Z
Source :
mitre
Researchers
Following researchers has claimed that they have found this vulnerability.
Onurcan Genç
@onurcangnc
AFFECTED PRODUCTS
The following products are affected by CVE-2025-57520 vulnerability.
| Vendors | Products |
|---|---|
| Techhub.p-m |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-57520.