CVE-2025-27802

Severity CVSS v4.0:
MEDIUM
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
28/07/2025
Last modified:
03/11/2025

Description

The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities. This allowed an authenticated attacker to execute malicious JavaScript code in the victim&amp;#39;s browser.<br /> <br /> RTE properties (text fields), which could be used in the "Edit" section of the CMS,<br /> allowed the input of arbitrary text. It was possible to input malicious JavaScript <br /> code in these properties that would be executed if a user visits the previewed <br /> page. Attackers needed at least the role "WebEditor" in order to exploit this issue.<br /> <br /> Affected products: Version 11.X: EPiServer.CMS.Core (