CVE-2025-11289
westboy CicadasCMS Template Management TemplateFileServiceImpl.java save cross site scripting
CVSS Score
2.4
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability was determined in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab. The impacted element is the function Save of the file src/main/java/com/zhiliao/common/template/TemplateFileServiceImpl.java of the component Template Management Page. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
| CWE | CWE-79 CWE-94 |
| Vendor | westboy |
| Product | cicadascms |
| Published | Oct 5, 2025 |
| Last Updated | Feb 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for westboy cicadascms
Be the first to know when new low vulnerabilities affecting westboy cicadascms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
westboy / CicadasCMS
2431154dac8d0735e04f1fd2a3c3556668fc8dab
References
Credits
๐ xmttz (VulDB User)