CVE-2025-1798

T

he does not sanitise and escape some parameters when outputting them back in a page, allowing unauthenticated users the ability to perform stored Cross-Site Scripting attacks.

References
Configurations

Configuration 1 (hide)

cpe:2.3:a:italia:design_comuni_italia:*:*:*:*:*:wordpress:*:*

History

15 Jan 2026, 19:49

Type Values Removed Values Added
CPE cpe:2.3:a:developers.italia:design_comuni_wordpress_theme:*:*:*:*:*:wordpress:*:* cpe:2.3:a:italia:design_comuni_italia:*:*:*:*:*:wordpress:*:*
First Time Italia
Italia design Comuni Italia

13 Jan 2026, 16:30

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/c5c30191-857c-419c-9096-d1fe14d34eaa/ - () https://wpscan.com/vulnerability/c5c30191-857c-419c-9096-d1fe14d34eaa/ - Exploit, Third Party Advisory
CPE cpe:2.3:a:developers.italia:design_comuni_wordpress_theme:*:*:*:*:*:wordpress:*:*
CWE CWE-352
First Time Developers.italia design Comuni Wordpress Theme
Developers.italia

27 Mar 2025, 16:45

Type Values Removed Values Added
Summary
  • (es) No depura ni escapa algunos parámetros al mostrarlos en una página, lo que permite que usuarios no autenticados tengan la capacidad de realizar ataques de cross site scripting almacenado.

25 Mar 2025, 14:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

25 Mar 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-25 06:15

Updated : 2026-01-15 19:49


NVD link : CVE-2025-1798

Mitre link : CVE-2025-1798

CVE.ORG link : CVE-2025-1798


JSON object : View

Products Affected
CWE
CWE-352

Cross-Site Request Forgery (CSRF)