github.com
https://github.com/publify/publify CVE-2021-25974
MEDIUM
Publify - Stored Cross-Site Scripting (XSS) in Editor
Record summary
CVE-2021-25974 has a selected CVSS score of 5.4 (medium).
Description
In Publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS. A user with a “publisher” role is able to inject and execute arbitrary JavaScript code while creating a page/article.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 30, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
publify_coreBrowse publify_core / publify_core | CVE List | v8.0 | affected |
| Through v9.2.4 | affected | ||
publify_coreBrowse RubyGems / publify_core | GitHub Advisory | 8.0 to < 9.2.5 · Fixed in 9.2.5 | affected |
References
4github.com
https://github.com/publify/publify/commit/fefd5f76302adcc425b2b6e7e7d23587cfc0083e nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-25974 whitesourcesoftware.com
https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25974