Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-59903

Опубликовано: 16 фев. 2026
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

Stored Cross-Site Scripting (XSS) vulnerability in Kubysoft, where uploaded SVG images are not properly sanitized. This allows attackers to embed malicious scripts within SVG files as visual content, which are then stored on the server and executed in the context of any user accessing the compromised resource.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:kubysoft:kubysoft:-:*:*:*:*:*:*:*

EPSS

Процентиль: 3%
0.00133
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
github
4 месяца назад

Stored Cross-Site Scripting (XSS) vulnerability in Kubysoft, where uploaded SVG images are not properly sanitized. This allows attackers to embed malicious scripts within SVG files as visual content, which are then stored on the server and executed in the context of any user accessing the compromised resource.

EPSS

Процентиль: 3%
0.00133
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79