CVE-2025-53865: CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') in roundup-tracker Roundup
Severity: mediumType: vulnerabilityCVE-2025-53865
In Roundup before 2.5.0, XSS can occur via interaction between URLs and issue tracker templates (devel and responsive).
CVE-2025-53865: CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') in roundup-tracker Roundup
Medium
Published: Sun Jul 13 2025 (07/13/2025, 00:00:00 UTC)
Source: CVE Database V5
Vendor/Project: roundup-tracker
Product: Roundup
Description
In Roundup before 2.5.0, XSS can occur via interaction between URLs and issue tracker templates (devel and responsive).
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- mitre
- Date Reserved
- 2025-07-11T00:00:00.000Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 68740976a83201eaacbdea92
Added to database: 7/13/2025, 7:31:02 PM
Last updated: 7/13/2025, 7:31:02 PM
Views: 1
Related Threats
CVE-2025-7538: Unrestricted Upload in Campcodes Sales and Inventory System
MediumVulnerabilitySun Jul 13 2025
CVE-2025-7537: SQL Injection in Campcodes Sales and Inventory System
MediumVulnerabilitySun Jul 13 2025
CVE-2025-7536: SQL Injection in Campcodes Sales and Inventory System
MediumVulnerabilitySun Jul 13 2025
CVE-2025-7535: SQL Injection in Campcodes Sales and Inventory System
MediumVulnerabilitySun Jul 13 2025
CVE-2025-7534: SQL Injection in PHPGurukul Student Result Management System
MediumVulnerabilitySun Jul 13 2025
Actions
Please log in to the Console to use AI analysis features.
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.