CVE-2025-6050
MEDIUMMezzanine < 6.1.1 - Authenticated Stored Cross-Site Scripting via Blog Post Title in Admin Interface
Title source: llmDescription
Mezzanine CMS, in versions prior to 6.1.1, contains a Stored Cross-Site Scripting (XSS) vulnerability in the admin interface. The vulnerability exists in the "displayable_links_js" function, which fails to properly sanitize blog post titles before including them in JSON responses served via "/admin/displayable_links.js". An authenticated admin user can create a blog post with a malicious JavaScript payload in the title field, then trick another admin user into clicking a direct link to the "/admin/displayable_links.js" endpoint, causing the malicious script to execute in their browser.
References (3)
Core 3
Core References
Exploit, Third Party Advisory
https://advisory.checkmarx.net/advisory/CVE-2025-6050/
Issue Tracking
https://github.com/stephenmcd/mezzanine/discussions/2080
Scores
CVSS v3
4.8
EPSS
0.0008
EPSS Percentile
23.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (2)
jupo/mezzanine
< 6.1.1
pypi/Mezzanine
0 - 6.1.1PyPI
Published
Jun 17, 2025
Tracked Since
Feb 18, 2026