CVE-2025-27801 Details
Description
The Episerver Content Management System (CMS) by Optimizely was affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities. This allowed an authenticated attacker to execute malicious JavaScript code in the victim's browser. ContentReference properties, which could be used in the "Edit" section of the CMS, offered an upload functionality for documents. These documents could later be used as displayed content on the page. It was possible to upload SVG files that include malicious JavaScript code that would be executed if a user visited the direct URL of the preview image. Attackers needed at least the role "WebEditor" in order to exploit this issue. Affected products: Version 11.X: EPiServer.CMS.Core (<11.21.4) with EPiServer.CMS.UI (<11.37.5), Version 12.X: EPiServer.CMS.Core (<12.22.1) with EPiServer.CMS.UI (<11.37.3)
A stored cross-site scripting vulnerability has been identified in the Optimizely Episerver Content Management System (CMS) versions 11.X prior to 11.21.4 with EPiServer.CMS.UI through 11.37.5, and in version 12.X prior to 12.22.1 with EPiServer.CMS.UI prior to 11.37.3. This vulnerability allows authenticated attackers with at least a 'WebEditor' role to execute malicious JavaScript in the context of the victim's browser. The issue arises from the ability to upload SVG files containing harmful scripts through ContentReference properties, which could then be executed when the preview image URL is accessed.
Users can update to Optimizely Episerver CMS versions 11.21.4 or 12.22.1 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 28, 2025CISA-ADP
Assessed Jul 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://api.nuget.optimizely.com/packages/episerver.cms.core/11.21.4# | SEC Consult Vulnerability Lab | |
| https://api.nuget.optimizely.com/packages/episerver.cms.core/12.22.1# | SEC Consult Vulnerability Lab | |
| https://r.sec-consult.com/optimizely | SEC Consult Vulnerability Lab | |
| http://seclists.org/fulldisclosure/2025/Aug/18 | CVE |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | SEC Consult Vulnerability Lab |
Affected Products
| Product | Versions |
|---|---|
| Optimizely EPiServer.CMS.Core | < 11.21.4 (semver) < 12.22.1 (semver) |
CPE
Remediation
| |
| Optimizely EPiServer.CMS.UI | All versions |
CPE
Remediation
| |
| Optimizely EPiServer.Azure | All versions |
CPE
Remediation
| |
| Optimizely EPiServer.CloudPlatform.Cms | All versions |
CPE
Remediation
| |
| Optimizely EPiServer.Cms.WelcomeIntegration | All versions |
CPE
Remediation
| |
| Optimizely EPiServer.ContentDeliverApi | All versions |
CPE
Remediation
| |
| Optimizely EPiServer.OpenIDConnect | All versions |
CPE
Remediation
| |
| Optimizely EPiServer.Forms | All versions |
CPE
Remediation
| |
| Optimizely EPiServer.Labs.LanguageManager | All versions |
CPE
Remediation
| |
| Optimizely EPiServer.ConnectForMarketingAutomation | All versions |
CPE
Remediation
| |
| Optimizely EPiServer.MarketingAutomationIntegration.Marketo | All versions |
CPE
Remediation
| |
| Optimizely EPiServer.MarketingAutomationIntegration.Salesforce | All versions |
CPE
Remediation
| |
| Optimizely EPiServer.MarketingAutomationIntegration.ExactTarget | All versions |
CPE
Remediation
| |
| Optimizely EPiServer.CMS.TinyMce | All versions |
CPE
Remediation
| |
| Optimizely DXP | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | SEC Consult Vulnerability Lab |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 3, 2025 | CVE Modified | CVE |
| Jul 29, 2025 | CVE Modified | SEC Consult Vulnerability Lab |
| Jul 28, 2025 | CVE Modified | SEC Consult Vulnerability Lab |
| Jul 28, 2025 | New CVE Received | SEC Consult Vulnerability Lab |
Volerion