CVE 2.3 LOW

zhanglun lettura RSS ContentRender.tsx cross site scripting_CVE-2025-15454

2.3 / 10
LOW
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P

Description

A vulnerability was detected in zhanglun lettura up to 0.1.22. This issue affects some unknown processing of the file src/components/ArticleView/ContentRender.tsx of the component RSS Handler. The manipulation results in cross site scripting. The attack can be executed remotely. This attack is characterized by high complexity. The exploitability is assessed as difficult. The exploit is now public and may be used. The patch is identified as 67213093db9923e828a6e3fd8696a998c85da2d4. It is best practice to apply a patch to resolve this issue.

Basic Information

ID CVE-2025-15454
Source VulDB
Published Jan 5, 2026 at 03:02

Affected Product

Vendor zhanglun
Product lettura
Version 0.1.0
Affected Versions zhanglun lettura 0.1.0
zhanglun lettura 0.1.1
zhanglun lettura 0.1.2
zhanglun lettura 0.1.3
zhanglun lettura 0.1.4
zhanglun lettura 0.1.5
zhanglun lettura 0.1.6
zhanglun lettura 0.1.7
zhanglun lettura 0.1.8
zhanglun lettura 0.1.9
zhanglun lettura 0.1.10
zhanglun lettura 0.1.11
zhanglun lettura 0.1.12
zhanglun lettura 0.1.13
zhanglun lettura 0.1.14
zhanglun lettura 0.1.15
zhanglun lettura 0.1.16
zhanglun lettura 0.1.17
zhanglun lettura 0.1.18
zhanglun lettura 0.1.19
zhanglun lettura 0.1.20
zhanglun lettura 0.1.21
zhanglun lettura 0.1.22

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.