CVE-2025-27800
Severity CVSS v4.0:
MEDIUM
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
28/07/2025
Last modified:
03/11/2025
Description
The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities. This allowed an authenticated attacker to execute malicious JavaScript code in the victim&#39;s browser.<br />
<br />
<br />
<br />
The Admin dashboard offered the functionality to add gadgets to the dashboard.<br />
This included the "Notes" gadget. An authenticated attacker with the corresponding<br />
access rights (such as "WebAdmin") that was impersonating the victim could insert<br />
malicious JavaScript code in these notes that would be executed if the victim<br />
visited the dashboard.<br />
<br />
Affected products: Version 11.X: EPiServer.CMS.Core (
Impact
Base Score 4.0
4.80
Severity 4.0
MEDIUM
Base Score 3.x
4.80
Severity 3.x
MEDIUM



