CVE-2024-55341: Dotnetfoundation Piranha CMS

Medium severity, CVSS 4.7. EPSS: 0.5% chance of exploitation in the next 30 days.

A stored cross-site scripting (XSS) vulnerability in Piranha CMS 11.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by creating a page via the /manager/pages and then adding a markdown content with the XSS payload.

Affected products

Published 2024-12-20. Last modified 2026-06-17.