{"id":"GHSA-fxvx-gfmr-5xfj","summary":"Koillection Cross Site Scripting vulnerability ","details":"Cross Site Scripting vulnerability in Koillection v.1.6.10 allows a remote attacker to escalate privileges via the collection, Wishlist and album components","aliases":["CVE-2025-29746"],"modified":"2025-05-08T19:57:34.369353Z","published":"2025-05-07T21:31:45Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-05-08T19:28:55Z","nvd_published_at":"2025-05-07T19:16:07Z","cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-29746"},{"type":"WEB","url":"https://github.com/benjaminjonard/koillection/issues/1329"},{"type":"WEB","url":"https://gist.github.com/unklerunkle/73e2ab58d1a5b9129be5de55765ea4fe"},{"type":"PACKAGE","url":"https://github.com/benjaminjonard/koillection"},{"type":"WEB","url":"https://github.com/benjaminjonard/koillection/releases/tag/1.6.11"},{"type":"WEB","url":"https://github.com/benjaminjonard/koillection/releases/tag/1.6.12"}],"affected":[{"package":{"name":"koillection/koillection","ecosystem":"Packagist","purl":"pkg:composer/koillection/koillection"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.12"}]}],"versions":["1.1.7","1.2.0","1.2.1","1.2.2","1.2.3","1.2.4","1.2.5","1.3.0","1.3.1","1.3.10","1.3.11","1.3.12","1.3.13","1.3.14","1.3.15","1.3.16","1.3.17","1.3.18","1.3.2","1.3.3","1.3.4","1.3.5","1.3.6","1.3.7","1.3.8","1.3.9","1.4.0","1.4.1","1.4.10","1.4.11","1.4.12","1.4.13","1.4.2","1.4.3","1.4.4","1.4.5","1.4.6","1.4.7","1.4.8","1.4.9","1.5.0","1.5.1","1.5.10","1.5.11","1.5.12","1.5.13","1.5.14","1.5.15","1.5.2","1.5.3","1.5.4","1.5.5","1.5.6","1.5.7","1.5.8","1.5.9","1.6.0","1.6.1","1.6.10","1.6.11","1.6.2","1.6.3","1.6.4","1.6.5","1.6.6","1.6.7","1.6.8","1.6.9","v1.0.0","v1.0.1","v1.0.2","v1.0.3","v1.0.4","v1.1.0","v1.1.1","v1.1.2","v1.1.3","v1.1.4","v1.1.5","v1.1.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/05/GHSA-fxvx-gfmr-5xfj/GHSA-fxvx-gfmr-5xfj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}