CVE-2025-66036 Details
Description
Retro is an online platform providing items of vintage collections. Prior to version 2.4.7, Retro is vulnerable to a cross-site scripting (XSS) in the input handling component. This issue has been patched in version 2.4.7.
A cross-site scripting (XSS) vulnerability has been identified in the Retro online platform, which specializes in vintage collections. This issue, present in versions prior to 2.4.7, arises from inadequate sanitization of user input in the input handling component. As a result, attackers can inject malicious JavaScript, potentially leading to session hijacking, credential theft, or the execution of arbitrary scripts in the context of the user's browser.
Users are advised to upgrade to version 2.4.7 or later, where this vulnerability has been patched. As a temporary measure, a strict Content Security Policy (CSP) can be enabled, and unsafe HTML or JavaScript content can be filtered server-side, although upgrading is strongly recommended.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 29, 2025CISA-ADP
Assessed Dec 1, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Anjaliavv51/Retro/security/advisories/GHSA-gvv6-p6h6-2vj2 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Anjaliavv51 Retro | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 29, 2025 | New CVE Received | [email protected] |
Volerion