Junglewise Threat Intelligence

CVE-2025-5420: juzaweb CMS allows cross-site scripting by uploading an SVG file

CVE-2025-5420 · Severity: low · CVSS 3.1 · Published 2025-06-02

Technologies: juzaweb/cms (Packagist). Vendors: Packagist.

Executive brief

juzaweb CMS allows cross-site scripting by uploading an SVG file

Affected products

  • Packagist juzaweb/cms

Related threats