Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Wagtail-CMS-XSS — Wagtail CMS 6.4.1 Stored XSS | Kitploit
Tools/GitHubGitHub/echobrt/wagtail-cms-xss
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubechobrt/wagtail-cms-xss

Wagtail-CMS-XSS

Wagtail CMS 6.4.1 Stored XSS

View Repository
1 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Website

Wagtail-6.4.1-CMS-XSS CVE-2025-45388

Wagtail CMS 6.4.1 Stored XSS

CMS Stored XSS Vulnerability PoC

Overview

This repository demonstrates a Stored XSS vulnerability found in the Wagtail 6.4.1 CMS platform. A malicious JavaScript is embedded in a PDF file, and every time a user clicks on the PDF, an XSS popup appears.

Steps to Reproduce

  1. Upload a PDF document that contains a malicious script, like the one provided in this repository. Ekran görüntüsü 2025-03-26 025701 Ekran görüntüsü 2025-03-26 025903

  2. Access the CMS and locate the malicious PDF.

  3. Click on the PDF link. Ekran görüntüsü 2025-03-26 034822

  4. The malicious JavaScript will trigger and display an XSS popup every time the PDF is opened.

Ekran görüntüsü 2025-03-26 030008

References

https://www.cve.org/CVERecord?id=CVE-2025-45388

Download Tool