CVE-2025-41000

LOW

BoomCMS v9.1.4 - XSS

Title source: llm
STIX 2.1

Description

Cross-Frame Scripting (XFS) vulnerability in BoomCMS v9.1.4 from UXB London. XFS is a web attack technique that exploits specific browser bugs to spy on users via JavaScript. This type of attack is based on social engineering and depends entirely on the browser chosen by the user, so it is perceived as a minor threat to web application security. This vulnerability only works in older browsers.

Scores

CVSS v4 2.1
EPSS 0.0006
EPSS Percentile 18.5%
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1021
Status published
Products (1)
BoomCMS/BoomCMS 9.1.4
Published Sep 03, 2025
Tracked Since Feb 18, 2026