CVE 6.9 MEDIUM

Cross-Site Scripting Vulnerability in QWC2_CVE-2025-11183

6.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/AU:N/RE:L

Description

Cross-Site Scripting vulnerability in attribute table in QGIS QWC2 <2025.08.14
allows an authorized attacker to plant arbitrary JavaScript code in the page

Basic Information

ID CVE-2025-11183
Source NCSC.ch
Published Oct 13, 2025 at 09:17

Affected Product

Vendor QGIS
Product QWC2
Affected Versions QGIS QWC2 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.