Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-49590


CryptPad is a collaboration suite. Prior to version 2025.3.0, the "Link Bouncer" functionality attempts to filter javascript URIs to prevent Cross-Site Scripting (XSS), however this can be bypassed. There is an "early allow" code path that happens before the URI's protocol/scheme is checked, which a maliciously crafted URI can follow. This issue has been patched in version 2025.3.0.


Published

2025-06-18T23:15:19.200

Last Modified

2025-08-11T18:18:19.470

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-692

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application xwiki cryptpad < 2025.3.0 Yes

References