Vulnerability Description
Schlix CMS before v2.2.9-5 is vulnerable to Cross Site Scripting (XSS). Due to lack of javascript sanitization in the login form, incorrect login attempts in logs are triggered as XSS in the admin panel.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schlix | Cms | < 2.2.9-5 |
Related Weaknesses (CWE)
References
- https://gist.github.com/akinerkisa/b22f4517a4011d049c5fc7fd3b29c9f2Third Party Advisory
- https://www.schlix.com/news/release/december-2025-errata-5-bug-fix-release.html#Vendor Advisory
FAQ
What is CVE-2025-67443?
CVE-2025-67443 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Schlix CMS before v2.2.9-5 is vulnerable to Cross Site Scripting (XSS). Due to lack of javascript sanitization in the login form, incorrect login attempts in logs are triggered as XSS in the admin pan...
How severe is CVE-2025-67443?
CVE-2025-67443 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-67443?
Check the references section above for vendor advisories and patch information. Affected products include: Schlix Cms.