{"id":"CVE-2025-71165","summary":"Typesetter CMS Reflected XSS via Status.php","details":"Typesetter CMS versions up to and including 5.1 contain a reflected cross-site scripting (XSS) vulnerability in the administrative interface within the Tools Status functionality. The path parameter is reflected into the HTML response without proper output encoding in include/admin/Tools/Status.php. An authenticated attacker can supply crafted input containing HTML or JavaScript, resulting in arbitrary script execution in the context of an authenticated user's browser session.","modified":"2026-08-12T03:51:13.803872687Z","published":"2026-01-14T18:28:21.375Z","database_specific":{"cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/71xxx/CVE-2025-71165.json","cna_assigner":"VulnCheck"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/71xxx/CVE-2025-71165.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-71165"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/typesetter-cms-reflected-xss-via-status-php"},{"type":"REPORT","url":"https://github.com/Typesetter/Typesetter/issues/709"},{"type":"PACKAGE","url":"https://github.com/Typesetter/Typesetter"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/typesetter/typesetter","events":[{"introduced":"0"},{"last_affected":"d02debf46bf934ede31d60cafe27976ec344869c"}],"database_specific":{"source":["AFFECTED_FIELD","CPE_RANGE"],"cpe":"cpe:2.3:a:typesettercms:typesetter:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"5.1"}]}}],"versions":["v5.1","v5.0.3","v5.0.2","v5.0.1","v5.0","5.0-rc4","v5.0-rc3","v5.0-rc2","v5.0-rc1","v5.0b2","v5.0b1","v4.6rc1","v4.6b3","v4.6b2","v4.6b1","v4.5","4.5rc2","4.5rc1","v4.5b1","v4.4rc2","v4.4rc1","v4.4b3","v4.4b2","v4.4b1","v4.3.4","v4.3.3","v4.3.2","v4.3.2rc2","v4.3.2rc1","v4.3.2b1","v4.3.1","v4.3","v4.3rc3","v4.3rc2","v4.3rc1","v4.3b2","v4.3b1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-71165.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}]}