CVE-2025-12330 is a cross-site scripting (XSS) vulnerability in Willow CMS up to version 1.4.0, specifically affecting the "Add Post Page" component. An authenticated attacker can inject malicious scripts into the 'title' or 'body' fields when adding an article, which can then be executed in a victim's browser. This vulnerability has a CVSS score of 4.8 (Medium), indicating a network-based attack with low attack complexity, requiring high privileges and user interaction, potentially leading to low confidentiality and integrity impacts. While the exploit has been publicly released, there is no evidence of active exploitation, nor is it listed in Metasploit, Nuclei, or ExploitDB, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.4.0CPE matchmatch criteria | cpe:2.3:a:matthewdeaves:willow_cms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.