github.com
https://github.com/publify/publify CVE-2021-25975
MEDIUM
Publify - Stored Cross-Site Scripting (XSS) due to Unrestricted File Upload
Record summary
CVE-2021-25975 has a selected CVSS score of 5.4 (medium).
Description
In publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS as a result of an unrestricted file upload. This issue allows a user with “publisher” role to inject malicious JavaScript via the uploaded html file.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 30, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
publify_coreBrowse publify_core / publify_core | CVE List | v8.0 | affected |
| Through v9.2.4 | affected | ||
publify_coreBrowse RubyGems / publify_core | GitHub Advisory | 8.0 to < 9.2.5 · Fixed in 9.2.5 | affected |
References
4github.com
https://github.com/publify/publify/commit/d99c0870d3dbbfde7febdc6cad33199b84770101 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-25975 whitesourcesoftware.com
https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25974