Vulnerability Description
A stored Cross Site Scripting vulnerability in the "related recommendations" feature in Ppress v.0.0.9 allows a remote attacker to execute arbitrary code via a crafted script to the article.title, article.category, and article.tags parameters.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Yandaozi | Ppress | 0.0.9 |
Related Weaknesses (CWE)
References
- https://gist.github.com/coleak2021/512acaa12ba0987499d560967acff1d1MitigationPatchThird Party Advisory
- https://github.com/yandaozi/PPress/issues/3ExploitIssue Tracking
FAQ
What is CVE-2025-25973?
CVE-2025-25973 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A stored Cross Site Scripting vulnerability in the "related recommendations" feature in Ppress v.0.0.9 allows a remote attacker to execute arbitrary code via a crafted script to the article.title, art...
How severe is CVE-2025-25973?
CVE-2025-25973 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-25973?
Check the references section above for vendor advisories and patch information. Affected products include: Yandaozi Ppress.