Vulnerability Description
A Reflected Cross Site Scripting (XSS) vulnerability was found in /index.php in FoxCMS v1.2.6. When a crafted script is sent via a GET request, it is reflected unsanitized into the HTML response. This permits execution of arbitrary JavaScript code when a logged-in user submits the malicious input.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Foxcms | Foxcms | 1.2.6 |
Related Weaknesses (CWE)
References
- https://www.notion.so/FoxCMS-V1-2-6-Reflected-XSS-in-index-php-2222b2fd021080589ExploitThird Party Advisory
FAQ
What is CVE-2025-55420?
CVE-2025-55420 is a vulnerability with a CVSS score of 8.8 (HIGH). A Reflected Cross Site Scripting (XSS) vulnerability was found in /index.php in FoxCMS v1.2.6. When a crafted script is sent via a GET request, it is reflected unsanitized into the HTML response. This...
How severe is CVE-2025-55420?
CVE-2025-55420 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-55420?
Check the references section above for vendor advisories and patch information. Affected products include: Foxcms Foxcms.