Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 26 Feb 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Altium on-prem Enterprise Server
|
|
| CPEs | cpe:2.3:a:altium:on-prem_enterprise_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Altium on-prem Enterprise Server
|
Fri, 23 Jan 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Altium
Altium aes |
|
| Vendors & Products |
Altium
Altium aes |
Thu, 22 Jan 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 22 Jan 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored cross-site scripting (XSS) vulnerability in the BOM Viewer in Altium AES 7.0.3 allows an authenticated attacker to inject arbitrary JavaScript into the Description field of a schematic, which is executed when the BOM Viewer renders the affected content. | |
| Title | Stored Cross-Site Scripting in AES BOM Viewer | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Altium
Published:
Updated: 2026-01-22T19:19:24.809Z
Reserved: 2025-02-23T21:02:12.105Z
Link: CVE-2025-27379
Updated: 2026-01-22T19:19:18.405Z
Status : Analyzed
Published: 2026-01-22T02:15:51.137
Modified: 2026-02-26T21:24:23.487
Link: CVE-2025-27379
No data.
OpenCVE Enrichment
Updated: 2026-01-22T10:07:56Z