CVE-2025-46041

Publication date

2025-06-09 00:00:00

Family

mitre

State

PUBLISHED

Description

A stored cross-site scripting (XSS) vulnerability in Anchor CMS v0.12.7 allows attackers to inject malicious JavaScript via the page description field in the page creation interface (/admin/pages/add).