8.7
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Description
Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)
Basic Information
ID
CVE-2025-25018
Source
elastic
Published
Oct 10, 2025 at 09:50
Modified
Oct 10, 2025 at 09:51
Affected Product
Vendor
Elastic
Product
Kibana
Version
7.0.0
Affected Versions
Elastic Kibana 7.0.0
Elastic Kibana 8.0.0
Elastic Kibana 8.19.0
Elastic Kibana 9.0.0
Elastic Kibana 9.1.0
Elastic Kibana 8.0.0
Elastic Kibana 8.19.0
Elastic Kibana 9.0.0
Elastic Kibana 9.1.0