CVE-2025-27800

Severity CVSS v4.0:
MEDIUM
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
28/07/2025
Last modified:
03/11/2025

Description

The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities. This allowed an authenticated attacker to execute malicious JavaScript code in the victim&amp;#39;s browser.<br /> <br /> <br /> <br /> The Admin dashboard offered the functionality to add gadgets to the dashboard.<br /> This included the "Notes" gadget. An authenticated attacker with the corresponding<br /> access rights (such as "WebAdmin") that was impersonating the victim could insert<br /> malicious JavaScript code in these notes that would be executed if the victim<br /> visited the dashboard.<br /> <br /> Affected products: Version 11.X: EPiServer.CMS.Core (