aimeos/ai-cms-grapesjs
Aimeos GrapesJS CMS extension
Activity
- Latest release
- 3mo ago
- Total releases
- 98
- Cadence
- ~5 days
- Last 12 months
- 24
Reach
- Stars
- —
Details
- License
- LGPL-3.0
- First release
- Apr 06, 2021
| Version | Released | |
|---|---|---|
2022.10.11
patch
|
2022.10.11
patch
Dependencies (7)
Changelog
Compare changes
|
|
2023.10.18
patch
|
2023.10.18
patch
Dependencies (7)
Changelog
Compare changes
|
|
2024.10.11
patch
|
2024.10.11
patch
Dependencies (7)
Changelog
Compare changes
|
|
2025.10.7
patch
|
2025.10.7
patch
Dependencies (7)
Changelog
Compare changes
|
|
2026.04.3
patch
|
2026.04.3
patch
Dependencies (6)
Changelog
Compare changes
|
|
2023.10.17
patch
| ||
2024.10.10
patch
| ||
2025.10.6
patch
| ||
2026.04.2
patch
| ||
2026.04.1
major
| ||
2025.10.5
patch
| ||
2025.10.4
patch
| ||
2021.10.9
patch
|
2021.10.9
patch
Dependencies (7)
Changelog
Compare changes
|
|
2022.10.10
patch
|
2022.10.10
patch
Dependencies (7)
Changelog
Compare changes
|
|
2023.10.16
patch
| ||
2024.10.9
patch
| ||
2025.10.3
patch
| ||
2021.10.8
patch
|
2021.10.8
patch
Dependencies (7)
Changelog
Compare changes
|
|
2022.10.9
patch
|
2022.10.9
patch
Dependencies (7)
Changelog
Compare changes
|
|
2023.10.15
patch
|
2023.10.15
patch
Dependencies (7)
Changelog
Compare changes
|
|
2024.10.8
patch
|
2024.10.8
patch
Dependencies (7)
Changelog
Compare changes
|
|
2025.10.2
patch
|
2025.10.2
patch
Dependencies (7)
Changelog
Compare changes
|
|
2025.10.1
minor
1 CVE
CVE-2025-66468
GHSA-424m-fj2q-g7vg
Dec 03, 2025
Aimeos GrapesJS CMS extension has possible stored XSS that's exploitable by authenticated editors
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactJavascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. WorkaroundIf the standard CSP rules are active (default in production mode), an exploit isn't possible. CreditsLwin Min Oo lwinminoo2244@gmail.com Affected versions
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.04.6
2021.07.1
2021.07.2
2021.07.3
2021.07.4
2021.07.5
2021.07.6
+ 64 more Show less
2021.07.7
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2023.04.1
2023.04.2
2023.07.1
2023.07.2
2023.07.3
2023.07.4
2023.10.1
2023.10.10
2023.10.11
2023.10.12
2023.10.13
2023.10.14
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2023.10.9
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.07.1
2024.07.2
2024.07.3
2024.10.1
2024.10.2
2024.10.3
2024.10.4
2024.10.5
2024.10.6
2024.10.7
2025.04.1
2025.04.2
2025.07.1
2025.07.2
2025.10.1
Fixed in
2021.10.8
2022.10.9
2023.10.15
2024.10.8
2025.10.2
References Updated Dec 03, 2025 · Source: OSV.dev |
2025.10.1
minor
Dependencies (6)
Changelog
Compare changes
|
|
2025.07.2
patch
1 CVE
CVE-2025-66468
GHSA-424m-fj2q-g7vg
Dec 03, 2025
Aimeos GrapesJS CMS extension has possible stored XSS that's exploitable by authenticated editors
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactJavascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. WorkaroundIf the standard CSP rules are active (default in production mode), an exploit isn't possible. CreditsLwin Min Oo lwinminoo2244@gmail.com Affected versions
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.04.6
2021.07.1
2021.07.2
2021.07.3
2021.07.4
2021.07.5
2021.07.6
+ 64 more Show less
2021.07.7
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2023.04.1
2023.04.2
2023.07.1
2023.07.2
2023.07.3
2023.07.4
2023.10.1
2023.10.10
2023.10.11
2023.10.12
2023.10.13
2023.10.14
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2023.10.9
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.07.1
2024.07.2
2024.07.3
2024.10.1
2024.10.2
2024.10.3
2024.10.4
2024.10.5
2024.10.6
2024.10.7
2025.04.1
2025.04.2
2025.07.1
2025.07.2
2025.10.1
Fixed in
2021.10.8
2022.10.9
2023.10.15
2024.10.8
2025.10.2
References Updated Dec 03, 2025 · Source: OSV.dev |
2025.07.2
patch
Dependencies (6)
Changelog
Compare changes
|
|
2025.07.1
minor
1 CVE
CVE-2025-66468
GHSA-424m-fj2q-g7vg
Dec 03, 2025
Aimeos GrapesJS CMS extension has possible stored XSS that's exploitable by authenticated editors
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactJavascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. WorkaroundIf the standard CSP rules are active (default in production mode), an exploit isn't possible. CreditsLwin Min Oo lwinminoo2244@gmail.com Affected versions
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.04.6
2021.07.1
2021.07.2
2021.07.3
2021.07.4
2021.07.5
2021.07.6
+ 64 more Show less
2021.07.7
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2023.04.1
2023.04.2
2023.07.1
2023.07.2
2023.07.3
2023.07.4
2023.10.1
2023.10.10
2023.10.11
2023.10.12
2023.10.13
2023.10.14
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2023.10.9
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.07.1
2024.07.2
2024.07.3
2024.10.1
2024.10.2
2024.10.3
2024.10.4
2024.10.5
2024.10.6
2024.10.7
2025.04.1
2025.04.2
2025.07.1
2025.07.2
2025.10.1
Fixed in
2021.10.8
2022.10.9
2023.10.15
2024.10.8
2025.10.2
References Updated Dec 03, 2025 · Source: OSV.dev | ||
2025.04.2
patch
1 CVE
CVE-2025-66468
GHSA-424m-fj2q-g7vg
Dec 03, 2025
Aimeos GrapesJS CMS extension has possible stored XSS that's exploitable by authenticated editors
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactJavascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. WorkaroundIf the standard CSP rules are active (default in production mode), an exploit isn't possible. CreditsLwin Min Oo lwinminoo2244@gmail.com Affected versions
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.04.6
2021.07.1
2021.07.2
2021.07.3
2021.07.4
2021.07.5
2021.07.6
+ 64 more Show less
2021.07.7
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2023.04.1
2023.04.2
2023.07.1
2023.07.2
2023.07.3
2023.07.4
2023.10.1
2023.10.10
2023.10.11
2023.10.12
2023.10.13
2023.10.14
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2023.10.9
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.07.1
2024.07.2
2024.07.3
2024.10.1
2024.10.2
2024.10.3
2024.10.4
2024.10.5
2024.10.6
2024.10.7
2025.04.1
2025.04.2
2025.07.1
2025.07.2
2025.10.1
Fixed in
2021.10.8
2022.10.9
2023.10.15
2024.10.8
2025.10.2
References Updated Dec 03, 2025 · Source: OSV.dev |
2025.04.2
patch
Dependencies (6)
Changelog
Compare changes
|
|
2025.04.1
major
1 CVE
CVE-2025-66468
GHSA-424m-fj2q-g7vg
Dec 03, 2025
Aimeos GrapesJS CMS extension has possible stored XSS that's exploitable by authenticated editors
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactJavascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. WorkaroundIf the standard CSP rules are active (default in production mode), an exploit isn't possible. CreditsLwin Min Oo lwinminoo2244@gmail.com Affected versions
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.04.6
2021.07.1
2021.07.2
2021.07.3
2021.07.4
2021.07.5
2021.07.6
+ 64 more Show less
2021.07.7
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2023.04.1
2023.04.2
2023.07.1
2023.07.2
2023.07.3
2023.07.4
2023.10.1
2023.10.10
2023.10.11
2023.10.12
2023.10.13
2023.10.14
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2023.10.9
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.07.1
2024.07.2
2024.07.3
2024.10.1
2024.10.2
2024.10.3
2024.10.4
2024.10.5
2024.10.6
2024.10.7
2025.04.1
2025.04.2
2025.07.1
2025.07.2
2025.10.1
Fixed in
2021.10.8
2022.10.9
2023.10.15
2024.10.8
2025.10.2
References Updated Dec 03, 2025 · Source: OSV.dev | ||
2024.10.7
patch
1 CVE
CVE-2025-66468
GHSA-424m-fj2q-g7vg
Dec 03, 2025
Aimeos GrapesJS CMS extension has possible stored XSS that's exploitable by authenticated editors
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactJavascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. WorkaroundIf the standard CSP rules are active (default in production mode), an exploit isn't possible. CreditsLwin Min Oo lwinminoo2244@gmail.com Affected versions
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.04.6
2021.07.1
2021.07.2
2021.07.3
2021.07.4
2021.07.5
2021.07.6
+ 64 more Show less
2021.07.7
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2023.04.1
2023.04.2
2023.07.1
2023.07.2
2023.07.3
2023.07.4
2023.10.1
2023.10.10
2023.10.11
2023.10.12
2023.10.13
2023.10.14
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2023.10.9
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.07.1
2024.07.2
2024.07.3
2024.10.1
2024.10.2
2024.10.3
2024.10.4
2024.10.5
2024.10.6
2024.10.7
2025.04.1
2025.04.2
2025.07.1
2025.07.2
2025.10.1
Fixed in
2021.10.8
2022.10.9
2023.10.15
2024.10.8
2025.10.2
References Updated Dec 03, 2025 · Source: OSV.dev |
2024.10.7
patch
Dependencies (6)
Changelog
Compare changes
|
|
2023.10.14
patch
1 CVE
CVE-2025-66468
GHSA-424m-fj2q-g7vg
Dec 03, 2025
Aimeos GrapesJS CMS extension has possible stored XSS that's exploitable by authenticated editors
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactJavascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. WorkaroundIf the standard CSP rules are active (default in production mode), an exploit isn't possible. CreditsLwin Min Oo lwinminoo2244@gmail.com Affected versions
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.04.6
2021.07.1
2021.07.2
2021.07.3
2021.07.4
2021.07.5
2021.07.6
+ 64 more Show less
2021.07.7
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2023.04.1
2023.04.2
2023.07.1
2023.07.2
2023.07.3
2023.07.4
2023.10.1
2023.10.10
2023.10.11
2023.10.12
2023.10.13
2023.10.14
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2023.10.9
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.07.1
2024.07.2
2024.07.3
2024.10.1
2024.10.2
2024.10.3
2024.10.4
2024.10.5
2024.10.6
2024.10.7
2025.04.1
2025.04.2
2025.07.1
2025.07.2
2025.10.1
Fixed in
2021.10.8
2022.10.9
2023.10.15
2024.10.8
2025.10.2
References Updated Dec 03, 2025 · Source: OSV.dev |
2023.10.14
patch
Dependencies (6)
Changelog
Compare changes
|
|
2024.10.6
patch
1 CVE
CVE-2025-66468
GHSA-424m-fj2q-g7vg
Dec 03, 2025
Aimeos GrapesJS CMS extension has possible stored XSS that's exploitable by authenticated editors
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactJavascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. WorkaroundIf the standard CSP rules are active (default in production mode), an exploit isn't possible. CreditsLwin Min Oo lwinminoo2244@gmail.com Affected versions
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.04.6
2021.07.1
2021.07.2
2021.07.3
2021.07.4
2021.07.5
2021.07.6
+ 64 more Show less
2021.07.7
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2023.04.1
2023.04.2
2023.07.1
2023.07.2
2023.07.3
2023.07.4
2023.10.1
2023.10.10
2023.10.11
2023.10.12
2023.10.13
2023.10.14
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2023.10.9
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.07.1
2024.07.2
2024.07.3
2024.10.1
2024.10.2
2024.10.3
2024.10.4
2024.10.5
2024.10.6
2024.10.7
2025.04.1
2025.04.2
2025.07.1
2025.07.2
2025.10.1
Fixed in
2021.10.8
2022.10.9
2023.10.15
2024.10.8
2025.10.2
References Updated Dec 03, 2025 · Source: OSV.dev | ||
2024.10.5
patch
1 CVE
CVE-2025-66468
GHSA-424m-fj2q-g7vg
Dec 03, 2025
Aimeos GrapesJS CMS extension has possible stored XSS that's exploitable by authenticated editors
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactJavascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. WorkaroundIf the standard CSP rules are active (default in production mode), an exploit isn't possible. CreditsLwin Min Oo lwinminoo2244@gmail.com Affected versions
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.04.6
2021.07.1
2021.07.2
2021.07.3
2021.07.4
2021.07.5
2021.07.6
+ 64 more Show less
2021.07.7
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2023.04.1
2023.04.2
2023.07.1
2023.07.2
2023.07.3
2023.07.4
2023.10.1
2023.10.10
2023.10.11
2023.10.12
2023.10.13
2023.10.14
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2023.10.9
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.07.1
2024.07.2
2024.07.3
2024.10.1
2024.10.2
2024.10.3
2024.10.4
2024.10.5
2024.10.6
2024.10.7
2025.04.1
2025.04.2
2025.07.1
2025.07.2
2025.10.1
Fixed in
2021.10.8
2022.10.9
2023.10.15
2024.10.8
2025.10.2
References Updated Dec 03, 2025 · Source: OSV.dev | ||
2023.10.13
patch
1 CVE
CVE-2025-66468
GHSA-424m-fj2q-g7vg
Dec 03, 2025
Aimeos GrapesJS CMS extension has possible stored XSS that's exploitable by authenticated editors
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactJavascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. WorkaroundIf the standard CSP rules are active (default in production mode), an exploit isn't possible. CreditsLwin Min Oo lwinminoo2244@gmail.com Affected versions
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.04.6
2021.07.1
2021.07.2
2021.07.3
2021.07.4
2021.07.5
2021.07.6
+ 64 more Show less
2021.07.7
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2023.04.1
2023.04.2
2023.07.1
2023.07.2
2023.07.3
2023.07.4
2023.10.1
2023.10.10
2023.10.11
2023.10.12
2023.10.13
2023.10.14
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2023.10.9
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.07.1
2024.07.2
2024.07.3
2024.10.1
2024.10.2
2024.10.3
2024.10.4
2024.10.5
2024.10.6
2024.10.7
2025.04.1
2025.04.2
2025.07.1
2025.07.2
2025.10.1
Fixed in
2021.10.8
2022.10.9
2023.10.15
2024.10.8
2025.10.2
References Updated Dec 03, 2025 · Source: OSV.dev | ||
2023.10.12
patch
1 CVE
CVE-2025-66468
GHSA-424m-fj2q-g7vg
Dec 03, 2025
Aimeos GrapesJS CMS extension has possible stored XSS that's exploitable by authenticated editors
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactJavascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. WorkaroundIf the standard CSP rules are active (default in production mode), an exploit isn't possible. CreditsLwin Min Oo lwinminoo2244@gmail.com Affected versions
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.04.6
2021.07.1
2021.07.2
2021.07.3
2021.07.4
2021.07.5
2021.07.6
+ 64 more Show less
2021.07.7
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2023.04.1
2023.04.2
2023.07.1
2023.07.2
2023.07.3
2023.07.4
2023.10.1
2023.10.10
2023.10.11
2023.10.12
2023.10.13
2023.10.14
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2023.10.9
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.07.1
2024.07.2
2024.07.3
2024.10.1
2024.10.2
2024.10.3
2024.10.4
2024.10.5
2024.10.6
2024.10.7
2025.04.1
2025.04.2
2025.07.1
2025.07.2
2025.10.1
Fixed in
2021.10.8
2022.10.9
2023.10.15
2024.10.8
2025.10.2
References Updated Dec 03, 2025 · Source: OSV.dev | ||
2024.10.4
patch
1 CVE
CVE-2025-66468
GHSA-424m-fj2q-g7vg
Dec 03, 2025
Aimeos GrapesJS CMS extension has possible stored XSS that's exploitable by authenticated editors
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactJavascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. WorkaroundIf the standard CSP rules are active (default in production mode), an exploit isn't possible. CreditsLwin Min Oo lwinminoo2244@gmail.com Affected versions
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.04.6
2021.07.1
2021.07.2
2021.07.3
2021.07.4
2021.07.5
2021.07.6
+ 64 more Show less
2021.07.7
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2023.04.1
2023.04.2
2023.07.1
2023.07.2
2023.07.3
2023.07.4
2023.10.1
2023.10.10
2023.10.11
2023.10.12
2023.10.13
2023.10.14
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2023.10.9
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.07.1
2024.07.2
2024.07.3
2024.10.1
2024.10.2
2024.10.3
2024.10.4
2024.10.5
2024.10.6
2024.10.7
2025.04.1
2025.04.2
2025.07.1
2025.07.2
2025.10.1
Fixed in
2021.10.8
2022.10.9
2023.10.15
2024.10.8
2025.10.2
References Updated Dec 03, 2025 · Source: OSV.dev | ||
2024.10.3
patch
1 CVE
CVE-2025-66468
GHSA-424m-fj2q-g7vg
Dec 03, 2025
Aimeos GrapesJS CMS extension has possible stored XSS that's exploitable by authenticated editors
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactJavascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. WorkaroundIf the standard CSP rules are active (default in production mode), an exploit isn't possible. CreditsLwin Min Oo lwinminoo2244@gmail.com Affected versions
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.04.6
2021.07.1
2021.07.2
2021.07.3
2021.07.4
2021.07.5
2021.07.6
+ 64 more Show less
2021.07.7
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2023.04.1
2023.04.2
2023.07.1
2023.07.2
2023.07.3
2023.07.4
2023.10.1
2023.10.10
2023.10.11
2023.10.12
2023.10.13
2023.10.14
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2023.10.9
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.07.1
2024.07.2
2024.07.3
2024.10.1
2024.10.2
2024.10.3
2024.10.4
2024.10.5
2024.10.6
2024.10.7
2025.04.1
2025.04.2
2025.07.1
2025.07.2
2025.10.1
Fixed in
2021.10.8
2022.10.9
2023.10.15
2024.10.8
2025.10.2
References Updated Dec 03, 2025 · Source: OSV.dev | ||
2024.10.2
patch
1 CVE
CVE-2025-66468
GHSA-424m-fj2q-g7vg
Dec 03, 2025
Aimeos GrapesJS CMS extension has possible stored XSS that's exploitable by authenticated editors
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactJavascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. WorkaroundIf the standard CSP rules are active (default in production mode), an exploit isn't possible. CreditsLwin Min Oo lwinminoo2244@gmail.com Affected versions
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.04.6
2021.07.1
2021.07.2
2021.07.3
2021.07.4
2021.07.5
2021.07.6
+ 64 more Show less
2021.07.7
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2023.04.1
2023.04.2
2023.07.1
2023.07.2
2023.07.3
2023.07.4
2023.10.1
2023.10.10
2023.10.11
2023.10.12
2023.10.13
2023.10.14
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2023.10.9
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.07.1
2024.07.2
2024.07.3
2024.10.1
2024.10.2
2024.10.3
2024.10.4
2024.10.5
2024.10.6
2024.10.7
2025.04.1
2025.04.2
2025.07.1
2025.07.2
2025.10.1
Fixed in
2021.10.8
2022.10.9
2023.10.15
2024.10.8
2025.10.2
References Updated Dec 03, 2025 · Source: OSV.dev | ||
2024.10.1
minor
1 CVE
CVE-2025-66468
GHSA-424m-fj2q-g7vg
Dec 03, 2025
Aimeos GrapesJS CMS extension has possible stored XSS that's exploitable by authenticated editors
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactJavascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. WorkaroundIf the standard CSP rules are active (default in production mode), an exploit isn't possible. CreditsLwin Min Oo lwinminoo2244@gmail.com Affected versions
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.04.6
2021.07.1
2021.07.2
2021.07.3
2021.07.4
2021.07.5
2021.07.6
+ 64 more Show less
2021.07.7
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2023.04.1
2023.04.2
2023.07.1
2023.07.2
2023.07.3
2023.07.4
2023.10.1
2023.10.10
2023.10.11
2023.10.12
2023.10.13
2023.10.14
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2023.10.9
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.07.1
2024.07.2
2024.07.3
2024.10.1
2024.10.2
2024.10.3
2024.10.4
2024.10.5
2024.10.6
2024.10.7
2025.04.1
2025.04.2
2025.07.1
2025.07.2
2025.10.1
Fixed in
2021.10.8
2022.10.9
2023.10.15
2024.10.8
2025.10.2
References Updated Dec 03, 2025 · Source: OSV.dev | ||
2023.10.11
patch
1 CVE
CVE-2025-66468
GHSA-424m-fj2q-g7vg
Dec 03, 2025
Aimeos GrapesJS CMS extension has possible stored XSS that's exploitable by authenticated editors
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactJavascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. WorkaroundIf the standard CSP rules are active (default in production mode), an exploit isn't possible. CreditsLwin Min Oo lwinminoo2244@gmail.com Affected versions
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.04.6
2021.07.1
2021.07.2
2021.07.3
2021.07.4
2021.07.5
2021.07.6
+ 64 more Show less
2021.07.7
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2023.04.1
2023.04.2
2023.07.1
2023.07.2
2023.07.3
2023.07.4
2023.10.1
2023.10.10
2023.10.11
2023.10.12
2023.10.13
2023.10.14
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2023.10.9
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.07.1
2024.07.2
2024.07.3
2024.10.1
2024.10.2
2024.10.3
2024.10.4
2024.10.5
2024.10.6
2024.10.7
2025.04.1
2025.04.2
2025.07.1
2025.07.2
2025.10.1
Fixed in
2021.10.8
2022.10.9
2023.10.15
2024.10.8
2025.10.2
References Updated Dec 03, 2025 · Source: OSV.dev | ||
2024.07.3
patch
1 CVE
CVE-2025-66468
GHSA-424m-fj2q-g7vg
Dec 03, 2025
Aimeos GrapesJS CMS extension has possible stored XSS that's exploitable by authenticated editors
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactJavascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. WorkaroundIf the standard CSP rules are active (default in production mode), an exploit isn't possible. CreditsLwin Min Oo lwinminoo2244@gmail.com Affected versions
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.04.6
2021.07.1
2021.07.2
2021.07.3
2021.07.4
2021.07.5
2021.07.6
+ 64 more Show less
2021.07.7
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2023.04.1
2023.04.2
2023.07.1
2023.07.2
2023.07.3
2023.07.4
2023.10.1
2023.10.10
2023.10.11
2023.10.12
2023.10.13
2023.10.14
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2023.10.9
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.07.1
2024.07.2
2024.07.3
2024.10.1
2024.10.2
2024.10.3
2024.10.4
2024.10.5
2024.10.6
2024.10.7
2025.04.1
2025.04.2
2025.07.1
2025.07.2
2025.10.1
Fixed in
2021.10.8
2022.10.9
2023.10.15
2024.10.8
2025.10.2
References Updated Dec 03, 2025 · Source: OSV.dev |
2024.07.3
patch
Dependencies (6)
Changelog
Compare changes
|
|
2024.07.2
patch
1 CVE
CVE-2025-66468
GHSA-424m-fj2q-g7vg
Dec 03, 2025
Aimeos GrapesJS CMS extension has possible stored XSS that's exploitable by authenticated editors
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactJavascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. WorkaroundIf the standard CSP rules are active (default in production mode), an exploit isn't possible. CreditsLwin Min Oo lwinminoo2244@gmail.com Affected versions
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.04.6
2021.07.1
2021.07.2
2021.07.3
2021.07.4
2021.07.5
2021.07.6
+ 64 more Show less
2021.07.7
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2023.04.1
2023.04.2
2023.07.1
2023.07.2
2023.07.3
2023.07.4
2023.10.1
2023.10.10
2023.10.11
2023.10.12
2023.10.13
2023.10.14
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2023.10.9
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.07.1
2024.07.2
2024.07.3
2024.10.1
2024.10.2
2024.10.3
2024.10.4
2024.10.5
2024.10.6
2024.10.7
2025.04.1
2025.04.2
2025.07.1
2025.07.2
2025.10.1
Fixed in
2021.10.8
2022.10.9
2023.10.15
2024.10.8
2025.10.2
References Updated Dec 03, 2025 · Source: OSV.dev | ||
2024.07.1
minor
1 CVE
CVE-2025-66468
GHSA-424m-fj2q-g7vg
Dec 03, 2025
Aimeos GrapesJS CMS extension has possible stored XSS that's exploitable by authenticated editors
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactJavascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. WorkaroundIf the standard CSP rules are active (default in production mode), an exploit isn't possible. CreditsLwin Min Oo lwinminoo2244@gmail.com Affected versions
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.04.6
2021.07.1
2021.07.2
2021.07.3
2021.07.4
2021.07.5
2021.07.6
+ 64 more Show less
2021.07.7
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2023.04.1
2023.04.2
2023.07.1
2023.07.2
2023.07.3
2023.07.4
2023.10.1
2023.10.10
2023.10.11
2023.10.12
2023.10.13
2023.10.14
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2023.10.9
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.07.1
2024.07.2
2024.07.3
2024.10.1
2024.10.2
2024.10.3
2024.10.4
2024.10.5
2024.10.6
2024.10.7
2025.04.1
2025.04.2
2025.07.1
2025.07.2
2025.10.1
Fixed in
2021.10.8
2022.10.9
2023.10.15
2024.10.8
2025.10.2
References Updated Dec 03, 2025 · Source: OSV.dev | ||
2024.04.6
patch
1 CVE
CVE-2025-66468
GHSA-424m-fj2q-g7vg
Dec 03, 2025
Aimeos GrapesJS CMS extension has possible stored XSS that's exploitable by authenticated editors
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactJavascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. WorkaroundIf the standard CSP rules are active (default in production mode), an exploit isn't possible. CreditsLwin Min Oo lwinminoo2244@gmail.com Affected versions
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.04.6
2021.07.1
2021.07.2
2021.07.3
2021.07.4
2021.07.5
2021.07.6
+ 64 more Show less
2021.07.7
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2023.04.1
2023.04.2
2023.07.1
2023.07.2
2023.07.3
2023.07.4
2023.10.1
2023.10.10
2023.10.11
2023.10.12
2023.10.13
2023.10.14
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2023.10.9
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.07.1
2024.07.2
2024.07.3
2024.10.1
2024.10.2
2024.10.3
2024.10.4
2024.10.5
2024.10.6
2024.10.7
2025.04.1
2025.04.2
2025.07.1
2025.07.2
2025.10.1
Fixed in
2021.10.8
2022.10.9
2023.10.15
2024.10.8
2025.10.2
References Updated Dec 03, 2025 · Source: OSV.dev |
2024.04.6
patch
Dependencies (6)
Changelog
Compare changes
|
|
2024.04.5
patch
1 CVE
CVE-2025-66468
GHSA-424m-fj2q-g7vg
Dec 03, 2025
Aimeos GrapesJS CMS extension has possible stored XSS that's exploitable by authenticated editors
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactJavascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. WorkaroundIf the standard CSP rules are active (default in production mode), an exploit isn't possible. CreditsLwin Min Oo lwinminoo2244@gmail.com Affected versions
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.04.6
2021.07.1
2021.07.2
2021.07.3
2021.07.4
2021.07.5
2021.07.6
+ 64 more Show less
2021.07.7
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2023.04.1
2023.04.2
2023.07.1
2023.07.2
2023.07.3
2023.07.4
2023.10.1
2023.10.10
2023.10.11
2023.10.12
2023.10.13
2023.10.14
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2023.10.9
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.07.1
2024.07.2
2024.07.3
2024.10.1
2024.10.2
2024.10.3
2024.10.4
2024.10.5
2024.10.6
2024.10.7
2025.04.1
2025.04.2
2025.07.1
2025.07.2
2025.10.1
Fixed in
2021.10.8
2022.10.9
2023.10.15
2024.10.8
2025.10.2
References Updated Dec 03, 2025 · Source: OSV.dev | ||
2024.04.4
patch
1 CVE
CVE-2025-66468
GHSA-424m-fj2q-g7vg
Dec 03, 2025
Aimeos GrapesJS CMS extension has possible stored XSS that's exploitable by authenticated editors
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactJavascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. WorkaroundIf the standard CSP rules are active (default in production mode), an exploit isn't possible. CreditsLwin Min Oo lwinminoo2244@gmail.com Affected versions
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.04.6
2021.07.1
2021.07.2
2021.07.3
2021.07.4
2021.07.5
2021.07.6
+ 64 more Show less
2021.07.7
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2023.04.1
2023.04.2
2023.07.1
2023.07.2
2023.07.3
2023.07.4
2023.10.1
2023.10.10
2023.10.11
2023.10.12
2023.10.13
2023.10.14
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2023.10.9
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.07.1
2024.07.2
2024.07.3
2024.10.1
2024.10.2
2024.10.3
2024.10.4
2024.10.5
2024.10.6
2024.10.7
2025.04.1
2025.04.2
2025.07.1
2025.07.2
2025.10.1
Fixed in
2021.10.8
2022.10.9
2023.10.15
2024.10.8
2025.10.2
References Updated Dec 03, 2025 · Source: OSV.dev | ||
2024.04.3
patch
1 CVE
CVE-2025-66468
GHSA-424m-fj2q-g7vg
Dec 03, 2025
Aimeos GrapesJS CMS extension has possible stored XSS that's exploitable by authenticated editors
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactJavascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. WorkaroundIf the standard CSP rules are active (default in production mode), an exploit isn't possible. CreditsLwin Min Oo lwinminoo2244@gmail.com Affected versions
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.04.6
2021.07.1
2021.07.2
2021.07.3
2021.07.4
2021.07.5
2021.07.6
+ 64 more Show less
2021.07.7
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2023.04.1
2023.04.2
2023.07.1
2023.07.2
2023.07.3
2023.07.4
2023.10.1
2023.10.10
2023.10.11
2023.10.12
2023.10.13
2023.10.14
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2023.10.9
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.07.1
2024.07.2
2024.07.3
2024.10.1
2024.10.2
2024.10.3
2024.10.4
2024.10.5
2024.10.6
2024.10.7
2025.04.1
2025.04.2
2025.07.1
2025.07.2
2025.10.1
Fixed in
2021.10.8
2022.10.9
2023.10.15
2024.10.8
2025.10.2
References Updated Dec 03, 2025 · Source: OSV.dev | ||
2024.04.2
patch
1 CVE
CVE-2025-66468
GHSA-424m-fj2q-g7vg
Dec 03, 2025
Aimeos GrapesJS CMS extension has possible stored XSS that's exploitable by authenticated editors
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactJavascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. WorkaroundIf the standard CSP rules are active (default in production mode), an exploit isn't possible. CreditsLwin Min Oo lwinminoo2244@gmail.com Affected versions
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.04.6
2021.07.1
2021.07.2
2021.07.3
2021.07.4
2021.07.5
2021.07.6
+ 64 more Show less
2021.07.7
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2023.04.1
2023.04.2
2023.07.1
2023.07.2
2023.07.3
2023.07.4
2023.10.1
2023.10.10
2023.10.11
2023.10.12
2023.10.13
2023.10.14
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2023.10.9
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.07.1
2024.07.2
2024.07.3
2024.10.1
2024.10.2
2024.10.3
2024.10.4
2024.10.5
2024.10.6
2024.10.7
2025.04.1
2025.04.2
2025.07.1
2025.07.2
2025.10.1
Fixed in
2021.10.8
2022.10.9
2023.10.15
2024.10.8
2025.10.2
References Updated Dec 03, 2025 · Source: OSV.dev | ||
2024.04.1
major
1 CVE
CVE-2025-66468
GHSA-424m-fj2q-g7vg
Dec 03, 2025
Aimeos GrapesJS CMS extension has possible stored XSS that's exploitable by authenticated editors
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactJavascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. WorkaroundIf the standard CSP rules are active (default in production mode), an exploit isn't possible. CreditsLwin Min Oo lwinminoo2244@gmail.com Affected versions
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.04.6
2021.07.1
2021.07.2
2021.07.3
2021.07.4
2021.07.5
2021.07.6
+ 64 more Show less
2021.07.7
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2023.04.1
2023.04.2
2023.07.1
2023.07.2
2023.07.3
2023.07.4
2023.10.1
2023.10.10
2023.10.11
2023.10.12
2023.10.13
2023.10.14
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2023.10.9
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.07.1
2024.07.2
2024.07.3
2024.10.1
2024.10.2
2024.10.3
2024.10.4
2024.10.5
2024.10.6
2024.10.7
2025.04.1
2025.04.2
2025.07.1
2025.07.2
2025.10.1
Fixed in
2021.10.8
2022.10.9
2023.10.15
2024.10.8
2025.10.2
References Updated Dec 03, 2025 · Source: OSV.dev | ||
2023.10.10
patch
1 CVE
CVE-2025-66468
GHSA-424m-fj2q-g7vg
Dec 03, 2025
Aimeos GrapesJS CMS extension has possible stored XSS that's exploitable by authenticated editors
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactJavascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. WorkaroundIf the standard CSP rules are active (default in production mode), an exploit isn't possible. CreditsLwin Min Oo lwinminoo2244@gmail.com Affected versions
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.04.6
2021.07.1
2021.07.2
2021.07.3
2021.07.4
2021.07.5
2021.07.6
+ 64 more Show less
2021.07.7
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2023.04.1
2023.04.2
2023.07.1
2023.07.2
2023.07.3
2023.07.4
2023.10.1
2023.10.10
2023.10.11
2023.10.12
2023.10.13
2023.10.14
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2023.10.9
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.07.1
2024.07.2
2024.07.3
2024.10.1
2024.10.2
2024.10.3
2024.10.4
2024.10.5
2024.10.6
2024.10.7
2025.04.1
2025.04.2
2025.07.1
2025.07.2
2025.10.1
Fixed in
2021.10.8
2022.10.9
2023.10.15
2024.10.8
2025.10.2
References Updated Dec 03, 2025 · Source: OSV.dev | ||
2023.10.9
patch
1 CVE
CVE-2025-66468
GHSA-424m-fj2q-g7vg
Dec 03, 2025
Aimeos GrapesJS CMS extension has possible stored XSS that's exploitable by authenticated editors
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactJavascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. WorkaroundIf the standard CSP rules are active (default in production mode), an exploit isn't possible. CreditsLwin Min Oo lwinminoo2244@gmail.com Affected versions
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.04.6
2021.07.1
2021.07.2
2021.07.3
2021.07.4
2021.07.5
2021.07.6
+ 64 more Show less
2021.07.7
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2023.04.1
2023.04.2
2023.07.1
2023.07.2
2023.07.3
2023.07.4
2023.10.1
2023.10.10
2023.10.11
2023.10.12
2023.10.13
2023.10.14
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2023.10.9
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.07.1
2024.07.2
2024.07.3
2024.10.1
2024.10.2
2024.10.3
2024.10.4
2024.10.5
2024.10.6
2024.10.7
2025.04.1
2025.04.2
2025.07.1
2025.07.2
2025.10.1
Fixed in
2021.10.8
2022.10.9
2023.10.15
2024.10.8
2025.10.2
References Updated Dec 03, 2025 · Source: OSV.dev | ||
2023.10.8
patch
1 CVE
CVE-2025-66468
GHSA-424m-fj2q-g7vg
Dec 03, 2025
Aimeos GrapesJS CMS extension has possible stored XSS that's exploitable by authenticated editors
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
ImpactJavascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. WorkaroundIf the standard CSP rules are active (default in production mode), an exploit isn't possible. CreditsLwin Min Oo lwinminoo2244@gmail.com Affected versions
2021.04.1
2021.04.2
2021.04.3
2021.04.4
2021.04.5
2021.04.6
2021.07.1
2021.07.2
2021.07.3
2021.07.4
2021.07.5
2021.07.6
+ 64 more Show less
2021.07.7
2021.10.1
2021.10.2
2021.10.3
2021.10.4
2021.10.5
2021.10.6
2021.10.7
2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.07.1
2022.07.2
2022.07.3
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2023.04.1
2023.04.2
2023.07.1
2023.07.2
2023.07.3
2023.07.4
2023.10.1
2023.10.10
2023.10.11
2023.10.12
2023.10.13
2023.10.14
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2023.10.9
2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6
2024.07.1
2024.07.2
2024.07.3
2024.10.1
2024.10.2
2024.10.3
2024.10.4
2024.10.5
2024.10.6
2024.10.7
2025.04.1
2025.04.2
2025.07.1
2025.07.2
2025.10.1
Fixed in
2021.10.8
2022.10.9
2023.10.15
2024.10.8
2025.10.2
References Updated Dec 03, 2025 · Source: OSV.dev |