CVE-2025-48203: XSS
Published May 21, 2025
·Updated
Cross-site scripting (XSS) vulnerability in the [clickstorm] SEO (csseo) TYPO3 extension allows backend users to execute arbitrary script via the JSON-LD output.
Other sources
The csseo extension through 9.2.0 for TYPO3 allows XSS.
— MITRE
Affected Software
5 affected componentsFixes available
Typo3 cs_seo<=9.2.0
composer/clickstorm/cs-seo>=6.3.0<6.8.0
6.8.0
composer/clickstorm/cs-seo>=7.0.0<7.5.0
7.5.0
composer/clickstorm/cs-seo>=8.0.0<8.4.0
8.4.0
composer/clickstorm/cs-seo>=9.0.0<9.3.0
9.3.0
Event History
May 21, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·05:18 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-48203?
CVE-2025-48203 is classified as a high severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2025-48203?
To fix CVE-2025-48203, upgrade the cs_seo extension to at least version 9.3.0.
3
Which versions of the cs_seo extension are affected by CVE-2025-48203?
CVE-2025-48203 affects versions of the cs_seo extension up to and including 9.2.0.
4
Who is affected by CVE-2025-48203?
CVE-2025-48203 affects backend users of the cs_seo TYPO3 extension.
5
What types of attacks can CVE-2025-48203 facilitate?
CVE-2025-48203 can facilitate arbitrary script execution through cross-site scripting (XSS) attacks.