
Anchor CMS 0.12.7 – Stored Cross Site Scripting (XSS)
# Exploit Title: Anchor CMS 0.12.7 – Stored Cross Site Scripting (XSS) # Google Dork: inurl:”/admin/pages/add” “Anchor CMS” # Date: 2025-06-08 # Exploit Author: /bin/neko # Vendor Homepage: http://anchorcms.com # Software Link: https://github.com/anchorcms/anchor-cms # Version: 0.12.7 # Tested on: Ubuntu 22.04 + Apache2 + PHP 8.1 # CVE: CVE-2025-46041 # Description: Anchor CMS v0.12.7…