4.8
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was identified in IbuyuCMS up to 2.6.3. Impacted is an unknown function of the file /admin/article.php?a=mod of the component Add Article Page. The manipulation of the argument Title leads to cross site scripting. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
Basic Information
ID
CVE-2025-10434
Source
VulDB
Published
Sep 15, 2025 at 08:32
Affected Product
Vendor
n/a
Product
IbuyuCMS
Version
2.6.0
Affected Versions
n/a IbuyuCMS 2.6.0
n/a IbuyuCMS 2.6.1
n/a IbuyuCMS 2.6.2
n/a IbuyuCMS 2.6.3
n/a IbuyuCMS 2.6.1
n/a IbuyuCMS 2.6.2
n/a IbuyuCMS 2.6.3