Description

A Cross Site Scripting (XSS) vulnerability exists in Decap CMS thru 3.8.3. Input fields such as body, tags, title, and description are not properly sanitized before being rendered in the content preview pane. This enables an attacker to inject arbitrary JavaScript which executes whenever a user views the preview panel. The vulnerability affects multiple input vectors and does not require user interaction beyond viewing the affected content.

INFO

Published Date :

2025-09-10T00:00:00.000Z

Last Modified :

2025-09-11T18:26:06.358Z

Source :

mitre

Researchers

Following researchers has claimed that they have found this vulnerability.

Onurcan Genç

@onurcangnc

AFFECTED PRODUCTS

The following products are affected by CVE-2025-57520 vulnerability.

Vendors Products
Techhub.p-m
  • Decap Cms
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-57520.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact