affected: - ecosystem_specific: {} package: ecosystem: PyPI name: mezzanine purl: pkg:pypi/mezzanine ranges: - events: - introduced: '0' - last_affected: 6.0.0 type: ECOSYSTEM versions: - '0.1' - 0.1.1 - 0.1.2 - 0.1.3 - 0.1.4 - '0.10' - 0.10.1 - 0.10.2 - 0.10.3 - 0.10.4 - 0.10.5 - 0.10.6 - '0.11' - 0.11.1 - 0.11.10 - 0.11.2 - 0.11.3 - 0.11.4 - 0.11.5 - 0.11.6 - 0.11.7 - 0.11.8 - 0.11.9 - '0.12' - 0.12.1 - 0.12.2 - 0.12.3 - 0.12.4 - 0.12.5 - '0.2' - 0.2.1 - 0.2.2 - 0.2.3 - 0.2.4 - 0.3.0 - 0.3.1 - 0.3.2 - 0.3.3 - 0.3.4 - 0.3.5 - '0.4' - 0.5.1 - 0.5.2 - 0.5.3 - 0.5.4 - '0.6' - 0.6.1 - 0.6.2 - 0.6.3 - 0.6.4 - '0.7' - 0.7.2 - '0.8' - 0.8.1 - 0.8.2 - 0.8.3 - 0.8.4 - 0.8.5 - '0.9' - 0.9.1 - 1.0.0 - 1.0.1 - 1.0.10 - 1.0.2 - 1.0.3 - 1.0.4 - 1.0.5 - 1.0.6 - 1.0.7 - 1.0.8 - 1.0.9 - 1.1.0 - 1.1.1 - 1.1.2 - 1.1.3 - 1.1.4 - 1.2.0 - 1.2.1 - 1.2.2 - 1.2.3 - 1.2.4 - 1.3.0 - 1.4.0 - 1.4.1 - 1.4.10 - 1.4.11 - 1.4.12 - 1.4.13 - 1.4.14 - 1.4.15 - 1.4.16 - 1.4.2 - 1.4.3 - 1.4.4 - 1.4.5 - 1.4.6 - 1.4.7 - 1.4.8 - 1.4.9 - 3.0.0 - 3.0.1 - 3.0.2 - 3.0.3 - 3.0.4 - 3.0.5 - 3.0.6 - 3.0.7 - 3.0.8 - 3.0.9 - 3.1.0 - 3.1.1 - 3.1.10 - 3.1.2 - 3.1.3 - 3.1.4 - 3.1.5 - 3.1.6 - 3.1.7 - 3.1.8 - 3.1.9 - 4.0.0 - 4.0.1 - 4.1.0 - 4.2.0 - 4.2.1 - 4.2.2 - 4.2.3 - 4.3.0 - 4.3.1 - 5.0.0 - 5.0.0a1 - 5.0.0rc1 - 5.1.0 - 5.1.1 - 5.1.2 - 5.1.3 - 5.1.4 - 6.0.0 aliases: - CVE-2025-29573 - GHSA-2544-hpcq-6g27 details: Cross-Site Scripting (XSS) vulnerability exists in Mezzanine CMS 6.0.0 in the "View Entries" feature within the Forms module. id: PYSEC-2025-136 modified: '2026-05-21T14:54:34.430938Z' published: '2025-05-05T19:15:55.653Z' references: - type: PACKAGE url: https://github.com/stephenmcd/mezzanine - type: EVIDENCE url: https://www.squadappsec.com/post/cve-2025-29573-persistent-xss-in-mezzanine-cms-6-0-0-via-malicious-filename - type: ADVISORY url: https://github.com/advisories/GHSA-2544-hpcq-6g27 severity: - score: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N type: CVSS_V3