MEDIUM
GHSA-3qcp-9v8c-6jp7
Piranha CMS vulnerable to stored cross-site scripting (XSS)
Details
A stored cross-site scripting (XSS) vulnerability in the /manager/pages component of Piranha CMS v12.0 allows attackers to execute arbitrary web scripts or HTML via creating a page and injecting a crafted payload into the Markdown blocks.
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/Piranha
Introduced in:
0No fixed version published yet for Piranha (nuget). Pin to a known-safe version or switch to an alternative.