๐Ÿ” CVE Alert

CVE-2025-11289

LOW 2.4

westboy CicadasCMS Template Management TemplateFileServiceImpl.java save cross site scripting

CVSS Score
2.4
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was determined in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab. The impacted element is the function Save of the file src/main/java/com/zhiliao/common/template/TemplateFileServiceImpl.java of the component Template Management Page. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

CWE CWE-79 CWE-94
Vendor westboy
Product cicadascms
Published Oct 5, 2025
Last Updated Feb 24, 2026
Stay Ahead of the Next One

Get instant alerts for westboy cicadascms

Be the first to know when new low vulnerabilities affecting westboy cicadascms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

westboy / CicadasCMS
2431154dac8d0735e04f1fd2a3c3556668fc8dab

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/?id.327170 vuldb.com: https://vuldb.com/?ctiid.327170 vuldb.com: https://vuldb.com/?submit.659789 vuldb.com: https://vuldb.com/?submit.709804 github.com: https://github.com/devastatingglamour/CVE/blob/main/CicadasCMS-XSS4.md

Credits

๐Ÿ” xmttz (VulDB User)