CVE-2025-57520

MEDIUM

Techhub.p-m Decap Cms < 3.8.3 - XSS

Title source: rule

Description

A Cross Site Scripting (XSS) vulnerability exists in Decap CMS thru 3.8.3. Input fields such as body, tags, title, and description are not properly sanitized before being rendered in the content preview pane. This enables an attacker to inject arbitrary JavaScript which executes whenever a user views the preview panel. The vulnerability affects multiple input vectors and does not require user interaction beyond viewing the affected content.

Exploits (1)

nomisec WRITEUP
by onurcangnc · poc
https://github.com/onurcangnc/CVE-2025-57520-Stored-XSS-in-Decap-CMS-3.8.3-

Scores

CVSS v3 6.1
EPSS 0.0001
EPSS Percentile 1.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
npm/decap-cms 0npm
techhub.p-m/decap_cms < 3.8.3
Published Sep 10, 2025
Tracked Since Feb 18, 2026