{"id":"CVE-2025-6050","aliases":["GHSA-7pr5-w74r-jjj7","PYSEC-2025-236"],"url":"https://o3.security/vulnerability/CVE-2025-6050","summary":"Stored Cross-Site Scripting (XSS) in Mezzanine CMS Admin Interface","details":"Mezzanine CMS, in versions prior to 6.1.1, contains a Stored Cross-Site Scripting (XSS) vulnerability in the admin interface. The vulnerability exists in the \"displayable_links_js\" function, which fails to properly sanitize blog post titles before including them in JSON responses served via \"/admin/displayable_links.js\". An authenticated admin user can create a blog post with a malicious JavaScript payload in the title field, then trick another admin user into clicking a direct link to the \"/admin/displayable_links.js\" endpoint, causing the malicious script to execute in their browser.","published":"2025-06-17T11:06:12.360Z","modified":"2026-08-12T03:51:24.286746777Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"mezzanine","fixedVersion":"6.1.1"}],"fix":{"url":"https://github.com/stephenmcd/mezzanine/commit/898630d8df48cf3ddb8b9942f59168b93216e3f8","label":"stephenmcd/mezzanine@898630d"},"references":[{"type":"WEB","url":"https://github.com/stephenmcd/mezzanine/discussions/2080"},{"type":"WEB","url":"https://pypi.python.org"},{"type":"ADVISORY","url":"https://advisory.checkmarx.net/advisory/CVE-2025-6050/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/6xxx/CVE-2025-6050.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-6050"},{"type":"FIX","url":"https://github.com/stephenmcd/mezzanine/commit/898630d8df48cf3ddb8b9942f59168b93216e3f8"},{"type":"PACKAGE","url":"https://github.com/stephenmcd/mezzanine"},{"type":"WEB","url":"https://advisory.checkmarx.net/advisory/CVE-2025-6050"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-7pr5-w74r-jjj7"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/mezzanine/PYSEC-2025-236.yaml"},{"type":"WEB","url":"https://https://github.com/stephenmcd/mezzanine/commit/898630d8df48cf3ddb8b9942f59168b93216e3f8"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:24.286746777Z"}}