8.7
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Description
Improper Neutralization of Input During Web Page Generation in Kibana can lead to Stored XSS via case file upload.
Basic Information
ID
CVE-2025-25009
Source
elastic
Published
Oct 7, 2025 at 13:59
Affected Product
Vendor
Elastic
Product
Kibana
Version
7.0.0
Affected Versions
Elastic Kibana 7.0.0
Elastic Kibana 8.14.0
Elastic Kibana 8.19.0
Elastic Kibana 9.0.0
Elastic Kibana 9.1.0
Elastic Kibana 8.14.0
Elastic Kibana 8.19.0
Elastic Kibana 9.0.0
Elastic Kibana 9.1.0