CVE-2025-52131 Information

Description

The Mocca Calendar application before 2.15 for XWiki allows XSS via the background or text color field.

Reference

https://extensions.xwiki.org/xwiki/bin/view/Extension/MoccaCalendar https://github.com/xwiki-contrib/application-mocca-calendar https://github.com/xwikisas/application-mocca-calendar https://github.com/xwikisas/application-mocca-calendar/security/advisories/GHSA-jvq4-j2qw-q7x2

CNNVD-202508-167 (Published: 2025-08-03)

Share on: