CVE 5.1 MEDIUM

Multiple vulnerabilities in Kubysoft_CVE-2025-59903

5.1 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:L/SI:L/SA:N

Description

Stored Cross-Site Scripting (XSS) vulnerability in Kubysoft, where uploaded SVG images are not properly sanitized. This allows attackers to embed malicious scripts within SVG files as visual content, which are then stored on the server and executed in the context of any user accessing the compromised resource.

Basic Information

ID CVE-2025-59903
Source INCIBE
Published Feb 16, 2026 at 09:55

Affected Product

Vendor Kubysoft
Product Kubysoft
Version All versions
Affected Versions Kubysoft Kubysoft All versions

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.