Vulnerability Research
CVE-2025-57520 – Stored XSS in Decap CMS (<= 3.8.3)
A stored cross-site scripting (XSS) vulnerability exists in Decap CMS up to version 3.8.3. The issue affects multiple input fields in the admin interface and is triggered when a privileged user opens the content preview panel of a malicious entry. Vulnerability Summary * CVE ID: CVE-2025-57520 * Type: Stored Cross-Site