---
id: CVE-2025-11069
title: A vulnerability was determined in westboy CicadasCMS 1.0
summary: >-
  A vulnerability was determined in westboy CicadasCMS 1.0. Affected by this
  issue is some unknown functionality of the file /system/org/save of the
  component Add Department Handler. This manipulation of the argument Name
  causes cross site…
severity: low
cvss: 2.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
  - CWE-94
vendor: westboy
product: cicadascms
affected:
  - cicadascms = 1.0
published: '2025-09-27'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11069'
references:
  - url: 'https://github.com/devastatingglamour/CVE/blob/main/CicadasCMS-XSS3.md'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.326108'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.326108'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.659653'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00295
epssPercentile: 0.19983
ingestedAt: '2026-09-30T23:29:32.406Z'
---

## Overview

A vulnerability was determined in westboy CicadasCMS 1.0. Affected by this issue is some unknown functionality of the file /system/org/save of the component Add Department Handler. This manipulation of the argument Name causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

## Affected

- `cicadascms = 1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
