7
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/S:P/AU:N/R:U/V:D/RE:H/U:Red
Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Web Site Management Server allows Reflected XSS. The vulnerability could allow injecting malicious JavaScript inside URL parameters that was then rendered with the preview of the page, so that malicious scripts could be executed on the client side.
This issue affects Web Site Management Server: 16.7.0, 16.7.1.
This issue affects Web Site Management Server: 16.7.0, 16.7.1.
Basic Information
ID
CVE-2025-13672
Source
OpenText
Published
Feb 19, 2026 at 22:36
Affected Product
Vendor
OpenText™
Product
Web Site Management Server
Version
16.7.0
Affected Versions
OpenText™ Web Site Management Server 16.7.0
OpenText™ Web Site Management Server 16.7.1
OpenText™ Web Site Management Server 16.7.1