Threats Tagged 'cve-2025-65858'
View all threats tagged with 'cve-2025-65858'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-65858'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2025-65858 is a stored Cross-Site Scripting (XSS) vulnerability in Calibre-Web v0.6.25 that allows attackers with user creation privileges to inject malicious JavaScript into the username field. This payload is stored unsanitized and executed when the /ajax/listusers endpoint is accessed, potentially leading to limited confidentiality and integrity impacts. The vulnerability requires authenticated access and user interaction to trigger. Although the CVSS score is low (3.5), the flaw could be leveraged in targeted attacks within environments using Calibre-Web. No known exploits are currently reported in the wild, and no patches have been published yet. European organizations using Calibre-Web should be aware of this vulnerability and implement mitigations to prevent exploitation. Countries with higher adoption of Calibre-Web or with strategic interest in digital libraries and document management may be more affected. Join the discussion | CVE Database V5 | 12/02/2025, 00:00:00 UTC Added: 12/02/2025, 13:58:51 UTC |
Showing 1 to 1 of 1 result