7.2
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Description
Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated user to embed a malicious script in content that will be served to web browsers causing cross-site scripting (XSS) (CAPEC-63) via a method in Vega bypassing a previous Vega XSS mitigation.
Basic Information
ID
CVE-2025-68385
Source
elastic
Published
Dec 18, 2025 at 22:08
Affected Product
Vendor
Elastic
Product
Kibana
Version
7.0.0
Affected Versions
Elastic Kibana 7.0.0
Elastic Kibana 8.0.0
Elastic Kibana 9.0.0
Elastic Kibana 9.2.0
Elastic Kibana 8.0.0
Elastic Kibana 9.0.0
Elastic Kibana 9.2.0