CVE-2025-60869 is a persistent Cross-Site Scripting (XSS) vulnerability in Publii CMS v0.46.5 (build 17089), allowing attackers to inject malicious JavaScript into configuration fields like "Site Description" and "Footer Follow Buttons." This vulnerability carries a CVSS score of 7.3 (HIGH), indicating a high potential for impact, as the injected script executes in visitors' browsers when viewing the generated static site. While the attack requires low privileges and user interaction, it has not been observed in active exploitation, and there are no public exploits or significant community discussion surrounding it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | N/A | n/aCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.