CVE-2025-48305: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in vikingjs Goal Tracker for Patreon
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vikingjs Goal Tracker for Patreon allows Stored XSS. This issue affects Goal Tracker for Patreon: from n/a through 0.4.6.
CVE-2025-48305: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in vikingjs Goal Tracker for Patreon
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vikingjs Goal Tracker for Patreon allows Stored XSS. This issue affects Goal Tracker for Patreon: from n/a through 0.4.6.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- Patchstack
- Date Reserved
- 2025-05-19T14:13:45.513Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 68b0537dad5a09ad006cfc46
Added to database: 8/28/2025, 1:02:53 PM
Last updated: 8/28/2025, 1:05:50 PM
Views: 2
Actions
External Links
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.