{"id":"CVE-2025-71164","summary":"Typesetter CMS Reflected XSS via Editing.php","details":"Typesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the Editing component. The images parameter (submitted as images[] in a POST request) is reflected into an HTML href attribute without proper context-aware output encoding in include/tool/Editing.php. An authenticated attacker with editing privileges can supply a JavaScript pseudo-protocol (e.g., javascript:) to trigger arbitrary JavaScript execution in the context of the victim's browser session.","modified":"2026-08-12T03:51:23.051213181Z","published":"2026-01-14T18:27:45.418Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/71xxx/CVE-2025-71164.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/71xxx/CVE-2025-71164.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-71164"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/typesetter-cms-reflected-xss-via-editing-php"},{"type":"REPORT","url":"https://github.com/Typesetter/Typesetter/issues/706"},{"type":"PACKAGE","url":"https://github.com/Typesetter/Typesetter"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/typesetter/typesetter","events":[{"introduced":"0"},{"last_affected":"d02debf46bf934ede31d60cafe27976ec344869c"}],"database_specific":{"source":["AFFECTED_FIELD","CPE_RANGE"],"cpe":"cpe:2.3:a:typesettercms:typesetter:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"5.1"}]}}],"versions":["v5.1","v5.0.3","v5.0.2","v5.0.1","v5.0","5.0-rc4","v5.0-rc3","v5.0-rc2","v5.0-rc1","v5.0b2","v5.0b1","v4.6rc1","v4.6b3","v4.6b2","v4.6b1","v4.5","4.5rc2","4.5rc1","v4.5b1","v4.4rc2","v4.4rc1","v4.4b3","v4.4b2","v4.4b1","v4.3.4","v4.3.3","v4.3.2","v4.3.2rc2","v4.3.2rc1","v4.3.2b1","v4.3.1","v4.3","v4.3rc3","v4.3rc2","v4.3rc1","v4.3b2","v4.3b1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-71164.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}]}