CVE-2024-25873: Enhavo
Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.
Enhavo v0.13.1 was discovered to contain an HTML injection vulnerability in the Author text field under the Blockquote module. This vulnerability allows attackers to execute arbitrary code via a crafted payload.
Affected products
- Enhavo Enhavo: version 0.13.1 only
Published 2024-02-22. Last modified 2026-06-17.