CVE-2025-71166 | Typesetter CMS up to 5.1 Administrative Interface Status.php path cross site scripting (ID 707 / EUVD-2026-2434)
A vulnerability labeled as problematic has been found in Typesetter CMS up to 5.1. Impacted is an unknown function of the file include/admin/Tools/Status.php of the component Administrative Interface. The manipulation of the argument path results in cross site scripting. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability was named CVE-2025-71166. The attack may be performed from remote. There is no available exploit.