A AegiFlow
HIGHCVSS 8.6EPSS 0.4%

CVE-2025-66024

CVE-2025-66024 updated by NVD

Published
2026-03-04
Modified
2026-08-07
EPSS percentile
29%
Sources
github-advisory, nvd

Summary

The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions starting with 9.15 and prior to 9.15.7 are vulnerable to Stored Cross-Site Scripting (XSS) via the Blog Post Title. The vulnerability arises because the post title is injected directly into the HTML tag without proper escaping. An attacker with permissions to create or edit blog posts can inject malicious JavaScript into the title field. This script will execute in the browser of any user (including administrators) who views the blog post. This leads to potential session hijacking or privilege escalation. The vulnerability has been patched in the blog application version 9.15.7 by adding missing escaping. No known workarounds are available.

Affected packages

EcosystemPackageAffected versionsFixed versions
Mavenorg.xwiki.contrib.blog:application-blog-ui9.15.7

Remediation: Upgrade to 9.15.7 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.