ibexa/admin-ui-assets
External assets dependencies for Ibexa AdminUI
Activity
- Latest release
- 4w ago
- Total releases
- 133
- Cadence
- ~15 days
- Last 12 months
- 17
Reach
- Stars
- 4
Details
- License
- GPL-2.0-only OR custom
- First release
- Nov 16, 2021
| Version | Released | |
|---|---|---|
v5.0.10
patch
| ||
v4.6.32
patch
| ||
v5.0.9
patch
| ||
v4.6.31
patch
| ||
v5.0.8
patch
| ||
v4.6.30
patch
| ||
v6.0.0-alpha1
pre
| ||
v5.0.7
patch
| ||
v4.6.29
patch
| ||
v5.0.6
patch
| ||
v4.6.28
patch
| ||
v4.6.27
patch
| ||
v5.0.5
patch
| ||
v4.6.26
patch
| ||
v5.0.4
patch
| ||
v5.0.3
patch
| ||
v4.6.25
patch
| ||
v5.0.2
patch
| ||
v4.6.24
patch
| ||
v4.6.23
patch
| ||
v5.0.1
patch
| ||
v4.6.22
patch
| ||
v5.0.0
major
| ||
v5.0.0-rc1
pre
| ||
v5.0.0-beta2
pre
| ||
v4.6.21
patch
| ||
v5.0.0-beta1
pre
| ||
v5.0.0-alpha6
pre
| ||
v4.6.20
patch
1 CVE
GHSA-vhgq-r8gx-5fpv
Jun 13, 2025
Ibexa Admin UI assets XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-alpha1
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
+ 16 more Show less
v4.6.13
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev | ||
v5.0.0-alpha5
pre
| ||
v5.0.0-alpha4
pre
| ||
v5.0.0-alpha3
pre
| ||
v4.6.19
patch
1 CVE
GHSA-vhgq-r8gx-5fpv
Jun 13, 2025
Ibexa Admin UI assets XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-alpha1
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
+ 16 more Show less
v4.6.13
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev | ||
v4.6.18
patch
1 CVE
GHSA-vhgq-r8gx-5fpv
Jun 13, 2025
Ibexa Admin UI assets XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-alpha1
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
+ 16 more Show less
v4.6.13
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev | ||
v4.6.17
patch
1 CVE
GHSA-vhgq-r8gx-5fpv
Jun 13, 2025
Ibexa Admin UI assets XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-alpha1
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
+ 16 more Show less
v4.6.13
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev | ||
v5.0.0-alpha2
pre
| ||
v4.6.16
patch
1 CVE
GHSA-vhgq-r8gx-5fpv
Jun 13, 2025
Ibexa Admin UI assets XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-alpha1
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
+ 16 more Show less
v4.6.13
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev | ||
v4.6.15
patch
1 CVE
GHSA-vhgq-r8gx-5fpv
Jun 13, 2025
Ibexa Admin UI assets XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-alpha1
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
+ 16 more Show less
v4.6.13
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev | ||
v4.6.14
patch
1 CVE
GHSA-vhgq-r8gx-5fpv
Jun 13, 2025
Ibexa Admin UI assets XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-alpha1
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
+ 16 more Show less
v4.6.13
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev | ||
v4.6.13
patch
1 CVE
GHSA-vhgq-r8gx-5fpv
Jun 13, 2025
Ibexa Admin UI assets XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-alpha1
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
+ 16 more Show less
v4.6.13
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev | ||
v4.6.12
patch
1 CVE
GHSA-vhgq-r8gx-5fpv
Jun 13, 2025
Ibexa Admin UI assets XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-alpha1
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
+ 16 more Show less
v4.6.13
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev | ||
v4.6.11
patch
1 CVE
GHSA-vhgq-r8gx-5fpv
Jun 13, 2025
Ibexa Admin UI assets XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-alpha1
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
+ 16 more Show less
v4.6.13
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev | ||
v4.6.10
patch
1 CVE
GHSA-vhgq-r8gx-5fpv
Jun 13, 2025
Ibexa Admin UI assets XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-alpha1
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
+ 16 more Show less
v4.6.13
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev | ||
v4.6.9
patch
1 CVE
GHSA-vhgq-r8gx-5fpv
Jun 13, 2025
Ibexa Admin UI assets XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-alpha1
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
+ 16 more Show less
v4.6.13
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev | ||
v4.6.8
patch
1 CVE
GHSA-vhgq-r8gx-5fpv
Jun 13, 2025
Ibexa Admin UI assets XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-alpha1
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
+ 16 more Show less
v4.6.13
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev | ||
v4.6.7
patch
1 CVE
GHSA-vhgq-r8gx-5fpv
Jun 13, 2025
Ibexa Admin UI assets XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-alpha1
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
+ 16 more Show less
v4.6.13
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev | ||
v4.6.6
patch
1 CVE
GHSA-vhgq-r8gx-5fpv
Jun 13, 2025
Ibexa Admin UI assets XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-alpha1
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
+ 16 more Show less
v4.6.13
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev | ||
v4.6.5
patch
1 CVE
GHSA-vhgq-r8gx-5fpv
Jun 13, 2025
Ibexa Admin UI assets XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-alpha1
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
+ 16 more Show less
v4.6.13
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev | ||
v4.6.4
patch
1 CVE
GHSA-vhgq-r8gx-5fpv
Jun 13, 2025
Ibexa Admin UI assets XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-alpha1
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
+ 16 more Show less
v4.6.13
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev | ||
v4.6.3
patch
1 CVE
GHSA-vhgq-r8gx-5fpv
Jun 13, 2025
Ibexa Admin UI assets XSS vulnerabilities in back office
Medium
Network
Low
High
None
ImpactThis security advisory is a part of IBEXA-SA-2025-003, which resolves XSS vulnerabilities in several parts of the back office of Ibexa DXP. Back office access and varying levels of editing and management permissions are required to exploit these vulnerabilities. This typically means Editor or Administrator role, or similar. Injected XSS is persistent and can be reflected in the front office, possibly affecting end users. The fixes ensure XSS is escaped, and any existing injected XSS is rendered harmless. Patches
WorkaroundsNone. Affected versions
v4.6.0
v4.6.0-alpha1
v4.6.0-beta1
v4.6.0-beta2
v4.6.0-beta3
v4.6.0-beta4
v4.6.0-beta5
v4.6.0-rc1
v4.6.1
v4.6.10
v4.6.11
v4.6.12
+ 16 more Show less
v4.6.13
v4.6.14
v4.6.15
v4.6.16
v4.6.17
v4.6.18
v4.6.19
v4.6.2
v4.6.20
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
Fixed in
4.6.21
References
Updated Jun 13, 2025 · Source: OSV.dev |