Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The vulnerabilities has been fixed by the GDTaller team in the current version.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 27 Mar 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gdtaller:gdtaller:-:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Thu, 26 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 26 Mar 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Reflected Cross Site Scripting (XSS) vulnerabilities in GDTaller. These vulnerabilities allows an attacker execute JavaScript code in the victim's browser by sending a malicious URL en 'site' parameter in 'app_login.php'. | Reflected Cross Site Scripting (XSS) vulnerabilities in GDTaller. These vulnerabilities allows an attacker execute JavaScript code in the victim's browser by sending a malicious URL in 'site' parameter in 'app_login.php'. |
Thu, 26 Mar 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Reflected Cross Site Scripting (XSS) vulnerabilities in GDTaller. These vulnerabilities allows an attacker execute JavaScript code in the victim's browser by sending a malicious URL en 'site' parameter in 'app_login.php'. | |
| Title | Multiple vulnerabilities in GDTaller | |
| First Time appeared |
Gdtaller
Gdtaller gdtaller |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:gdtaller:gdtaller:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gdtaller
Gdtaller gdtaller |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-03-26T13:23:17.835Z
Reserved: 2025-04-16T09:09:26.929Z
Link: CVE-2025-41026
Updated: 2026-03-26T13:23:14.303Z
Status : Analyzed
Published: 2026-03-26T13:16:24.903
Modified: 2026-06-17T09:22:26.847
Link: CVE-2025-41026
No data.
OpenCVE Enrichment
Updated: 2026-03-27T20:26:15Z