github.com
https://github.com/owen2345/camaleon-cms CVE-2021-25969
MEDIUM
Camaleon CMS - Stored Cross-Site Scripting (XSS) in Comments
Record summary
CVE-2021-25969 has a selected CVSS score of 6.1 (medium).
Description
In Camaleon CMS application, versions 0.0.1 to 2.6.0 are vulnerable to stored XSS, that allows an unauthenticated attacker to store malicious scripts in the comments section of the post. These scripts are executed in a victim’s browser when they open the page containing the malicious comment.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 30, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
camaleon_cmsBrowse camaleon_cms / camaleon_cms | CVE List | 0.0.1 | affected |
| Through 2.6.0 | affected | ||
camaleon_cmsBrowse RubyGems / camaleon_cms | GitHub Advisory | 0.0.1 to < 2.6.0.1 · Fixed in 2.6.0.1 | affected |
References
4github.com
https://github.com/owen2345/camaleon-cms/commit/05506e9087bb05282c0bae6ccfe0283d0332ab3c nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-25969 whitesourcesoftware.com
https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25969