Aimeos GrapesJS CMS Extension Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in the Aimeos GrapesJS CMS extension, affecting versions 2021.04.1 prior to 2021.10.8, 2022.04.1 prior to 2022.10.9, 2023.04.1 prior to 2023.10.15, 2024.04.1 prior to 2024.10.8, and 2025.04.1 prior to 2025.10.2. The vulnerability allows malicious editors to inject JavaScript code, which can be executed later, if the standard Content Security Policy is disabled.

Impact

Exploitation of this vulnerability allows for the injection of JavaScript code, leading to a stored cross-site scripting attack, where the injected script is executed in the context of the user.

Remediation

Users can update to Aimeos GrapesJS CMS extension versions 2021.10.8, 2022.10.9, 2023.10.15, 2024.10.8, or 2025.10.2 to address this vulnerability. If the standard Content Security Policy rules are active, an exploit is not possible.

Added: Dec 2, 2025, 7:16 PM
Updated: Dec 2, 2025, 7:16 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
5.2
remediation
0.0
relevance
1.2
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.