PatchSiren

Zootemplate CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Zootemplate CVE published 2026-04-10

CVE-2025-58920

A Cross-site Scripting (XSS) vulnerability exists in the Cerato theme, affecting versions from n/a through 2.2.18. This issue allows for Reflected XSS attacks. The CVE record was published on 2026-04-10T14:16:25.283Z and has not been modified since then. The NVD entry is currently Deferred. Defenders and security teams should assess exposure and prioritize patching or mitigation. The vulnerability allows [truncated]