CVE-2025-27802
Severity CVSS v4.0:
MEDIUM
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
28/07/2025
Last modified:
03/11/2025
Description
The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities. This allowed an authenticated attacker to execute malicious JavaScript code in the victim&#39;s browser.<br />
<br />
RTE properties (text fields), which could be used in the "Edit" section of the CMS,<br />
allowed the input of arbitrary text. It was possible to input malicious JavaScript <br />
code in these properties that would be executed if a user visits the previewed <br />
page. Attackers needed at least the role "WebEditor" in order to exploit this issue.<br />
<br />
Affected products: Version 11.X: EPiServer.CMS.Core (
Impact
Base Score 4.0
4.80
Severity 4.0
MEDIUM
Base Score 3.x
4.80
Severity 3.x
MEDIUM



