4.8
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:L/AU:N/V:D
Description
SolarEdge monitoring platform contains a Cross‑Site Scripting (XSS) flaw that allows an authenticated user to inject payloads into report names, which may execute in a victim’s browser during a deletion attempt.
Basic Information
ID
CVE-2025-36746
Source
DIVD
Published
Dec 12, 2025 at 15:05
Affected Product
Vendor
SolarEdge
Product
SolarEdge Monitoring platform (SaaS)
Version
unkown
Affected Versions
SolarEdge SolarEdge Monitoring platform (SaaS) unkown