CVE-2025-52131

CVE Details

Basic Information

Title CVE-2025-52131
Type cve
Published 2025-08-03T00:00:00.000Z
Modified 2025-08-03T03:09:20.241Z

Product Information

Vendor xwiki-contrib
Product Mocca Calendar
Version 0

CVSS Information

Base Score 6.4 (MEDIUM)
Attack Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

AI Analysis

AI Description An XSS vulnerability in the Mocca Calendar allows attackers to inject malicious scripts via the background or text color field.
AI Severity Medium
AI Vendor XWiki Community
AI Product Mocca Calendar
AI Version 2.14 and earlier

Affected Products

  • xwiki-contrib Mocca Calendar 0

Additional Information

CWE List CWE-79
Source mitre

Description

The Mocca Calendar application before 2.15 for XWiki allows XSS via the background or text color field.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.