CVE-2025-66468: Aimeos Grapesjs CMS

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

The Aimeos GrapesJS CMS extension provides page editor for creating content pages based on extensible components. Prior to 2021.10.8, 2022.10.8, 2023.10.8, 2024.10.8, and 2025.10.8, Javascript code can be injected by malicious editors for a stored XSS attack if the standard Content Security Policy is disabled. This vulnerability is fixed in 2021.10.8, 2022.10.8, 2023.10.8, 2024.10.8, and 2025.10.8.

Affected products

  • Aimeos Grapesjs CMS: from 2021.04.1, before 2021.10.8 (fixed in 2021.10.8); from 2022.04.1, before 2022.10.9 (fixed in 2022.10.9); from 2023.04.1, before 2023.10.15 (fixed in 2023.10.15); from 2024.04.1, before 2024.10.8 (fixed in 2024.10.8); from 2025.04.1, before 2025.10.2 (fixed in 2025.10.2)

Published 2025-12-02. Last modified 2026-06-17.