Skip to main content

CVE-2025-53865: CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') in roundup-tracker Roundup

Medium
VulnerabilityCVE-2025-53865cvecve-2025-53865cwe-79
Published: Sun Jul 13 2025 (07/13/2025, 00:00:00 UTC)
Source: CVE Database V5
Vendor/Project: roundup-tracker
Product: Roundup

Description

In Roundup before 2.5.0, XSS can occur via interaction between URLs and issue tracker templates (devel and responsive).

Technical Details

Data Version
5.1
Assigner Short Name
mitre
Date Reserved
2025-07-11T00:00:00.000Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 68740976a83201eaacbdea92

Added to database: 7/13/2025, 7:31:02 PM

Last updated: 7/13/2025, 7:31:02 PM

Views: 1

Actions

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats