{"id":"CVE-2021-25977","details":"In PiranhaCMS, versions 7.0.0 to 9.1.1 are vulnerable to stored XSS due to the page title improperly sanitized. By creating a page with a specially crafted page title, a low privileged user can trigger arbitrary JavaScript execution.","aliases":["GHSA-jvjp-vh27-r9h5"],"modified":"2026-07-09T00:07:09.473834Z","published":"2021-10-25T13:15:07.800Z","references":[{"type":"ADVISORY","url":"https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25977"},{"type":"FIX","url":"https://github.com/PiranhaCMS/piranha.core/commit/543bc53c7dbd28c793ec960b57fb0e716c6b18d7"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/piranhacms/piranha.core","events":[{"introduced":"f0fc4d06ff4f1242d9d6a894ad04e89d6deef9af"},{"last_affected":"412ce5e9b5fe463bf85ed0a8d5799e75b864a38d"},{"fixed":"543bc53c7dbd28c793ec960b57fb0e716c6b18d7"}],"database_specific":{"cpe":"cpe:2.3:a:dotnetfoundation:piranha_cms:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"7.0.0"},{"last_affected":"9.1.1"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v9.1-sr1","v9.1","v9.1-beta1","v9.1-alpha2","v9.1-alpha1","v9.0-sr1","v9.0","v9.0-rc2","v9.0-rc1","v9.0-beta1","v8.4-sr3","v8.4-sr2","v8.4-sr1","v8.4","v8.3-sr2","v8.3-sr1","v8.3","v8.2","v8.1","v8.0-sr1","v8.0","v7.1.0","v7.0-sr5","v7.0-sr4","v7.0-sr3","v7.0-sr2","v7.0.1","v7.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-25977.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}