CVE-2025-2979

CVSS 3.1 Score 7.3 of 10 (high)

Details

Published Mar 31, 2025
Updated: Apr 1, 2025
CWE ID 416

Summary

CVE-2025-2979 is a newly disclosed cross-site scripting (XSS) vulnerability affecting WCMS 11. The issue lies in the Registration component's /index.php?anonymous/setregister file, specifically with the Username argument. An attacker can exploit this vulnerability remotely by manipulating the Username parameter, leading to the injection of malicious scripts. Although the vendor has been informed, they have yet to provide a patch or response to this disclosure. The public availability of the exploit increases the risk of successful attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share