We have already fixed the vulnerability in the following versions:
License Center 1.8.51 and later
License Center 1.9.51 and later
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
We have already fixed the vulnerability in the following versions: License Center 1.8.51 and later License Center 1.9.51 and later
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-26220 | A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: License Center 1.8.51 and later License Center 1.9.51 and later |
| Link | Providers |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-25-27 |
|
Fri, 05 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qnap
Qnap license Center |
|
| CPEs | cpe:2.3:a:qnap:license_center:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Qnap
Qnap license Center |
|
| Metrics |
cvssV3_1
|
Fri, 29 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 Aug 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: License Center 1.8.51 and later License Center 1.9.51 and later | |
| Title | License Center | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: qnap
Published:
Updated: 2025-08-29T17:14:55.555Z
Reserved: 2025-01-07T06:55:33.249Z
Link: CVE-2025-22483
Updated: 2025-08-29T17:14:49.416Z
Status : Analyzed
Published: 2025-08-29T17:15:33.877
Modified: 2025-12-05T21:09:44.810
Link: CVE-2025-22483
No data.
OpenCVE Enrichment
No data.
EUVD