Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-8618 | There is a XXE in W3CSS Validator versions before cssval-20250226 that allows an attacker to use specially-crafted XML objects to coerce server-side request forgery (SSRF). This could be exploited to read arbitrary local files if an attacker has access to exception messages. |
Fri, 01 Aug 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
W3
W3 css Validator |
|
| CPEs | cpe:2.3:a:w3:css_validator:*:*:*:*:*:*:*:* | |
| Vendors & Products |
W3
W3 css Validator |
|
| Metrics |
cvssV3_1
|
Fri, 28 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 28 Mar 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | There is a XXE in W3CSS Validator versions before cssval-20250226 that allows an attacker to use specially-crafted XML objects to coerce server-side request forgery (SSRF). This could be exploited to read arbitrary local files if an attacker has access to exception messages. | |
| Weaknesses | CWE-611 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Google
Published:
Updated: 2025-03-28T14:31:48.212Z
Reserved: 2025-02-28T15:27:33.252Z
Link: CVE-2025-1781
Updated: 2025-03-28T14:31:44.655Z
Status : Analyzed
Published: 2025-03-28T14:15:19.687
Modified: 2025-08-01T17:54:11.577
Link: CVE-2025-1781
No data.
OpenCVE Enrichment
Updated: 2025-07-12T15:26:25Z
EUVD