Untriaged
Permalink
CVE-2025-22703
7.1 HIGH
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): REQUIRED
- Scope (S): CHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): LOW
- Availability impact (A): LOW
WordPress Forge – Front-End Page Builder plugin <= 1.4.6 - CSRF to Stored Cross Site Scripting (XSS) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in manuelvicedo Forge – Front-End Page Builder allows Stored XSS. This issue affects Forge – Front-End Page Builder: from n/a through 1.4.6.
References
Affected products
forge
- =<1.4.6
Matching in nixpkgs
pkgs.forge
OpenGL interop library that can be used with ArrayFire or any other application using CUDA or OpenCL compute backend
pkgs.forgejo
Self-hosted lightweight software forge
pkgs.forge-mtg
Magic: the Gathering card game with rules enforcement
pkgs.mindforger
Thinking Notebook & Markdown IDE
pkgs.forgejo-cli
CLI application for interacting with Forgejo
pkgs.forgejo-lts
Self-hosted lightweight software forge
pkgs.mcdreforged
Rewritten version of MCDaemon, a python tool to control your Minecraft server
pkgs.forge-sparks
Get Git forges notifications
pkgs.fontforge-gtk
Font editor
pkgs.forgejo-runner
Runner for Forgejo based on act
pkgs.emacsPackages.forge
None
-
nixos-unstable 20241014.1340
- nixpkgs-unstable 20241014.1340
- nixos-unstable-small 20241014.1340
pkgs.fontforge-fonttools
Font editor
pkgs.gnomeExtensions.forge
Tiling and window manager for GNOME
pkgs.emacsPackages.orgit-forge
None
-
nixos-unstable 20240808.1947
- nixpkgs-unstable 20240808.1947
- nixos-unstable-small 20240808.1947
pkgs.python311Packages.fontforge
Font editor
pkgs.python312Packages.fontforge
Font editor
pkgs.emacsPackages.consult-gh-forge
None
-
nixos-unstable 20240927.1004
- nixpkgs-unstable 20240927.1004
- nixos-unstable-small 20240927.1004
Package maintainers
-
@erictapen Kerstin Humm <kerstin@erictapen.name>
-
@twesterhout Tom Westerhout
-
@chessai Daniel Cartwright <chessai1996@gmail.com>
-
@eigengrau Sebastian Reuße <seb@schattenkopie.de>
-
@michaelgrahamevans Michael Evans <michaelgrahamevans@gmail.com>
-
@bendlas Herwig Hochleitner <herwig@bendlas.net>
-
@adamcstephens Adam C. Stephens <happy.plan4249@valkor.net>
-
@urandom2 Colin Arnott <colin@urandom.co.uk>
-
@nycodeghg Marie Ramlow <tabmeier12+nix@gmail.com>
-
@emilylange Emily Lange <nix@emilylange.de>
-
@isabelroses Isabel Roses <isabel@isabelroses.com>
-
@Kranzes Ilan Joselevich <personal@ilanjoselevich.com>
-
@christoph-heiss Christoph Heiss <christoph@c8h4.io>
-
@honnip Jung seungwoo <me@honnip.page>
-
@cyplo Cyryl Płotnicki <nixos@cyplo.dev>