Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27508 | Cross-site scripting in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network access. |
| Link | Providers |
|---|---|
| https://www.zoom.com/en/trust/security-bulletin/ZSB-25034 |
|
Mon, 06 Oct 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zoom meeting Software Development Kit
Zoom rooms Zoom rooms Controller Zoom workplace Desktop Zoom workplace Virtual Desktop Infrastructure |
|
| CPEs | cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:android:*:* cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:linux:*:* cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:macos:*:* cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:windows:*:* cpe:2.3:a:zoom:rooms:*:*:*:*:*:android:*:* cpe:2.3:a:zoom:rooms:*:*:*:*:*:ipad_os:*:* cpe:2.3:a:zoom:rooms:*:*:*:*:*:macos:*:* cpe:2.3:a:zoom:rooms:*:*:*:*:*:windows:*:* cpe:2.3:a:zoom:rooms_controller:*:*:*:*:*:android:*:* cpe:2.3:a:zoom:rooms_controller:*:*:*:*:*:linux:*:* cpe:2.3:a:zoom:rooms_controller:*:*:*:*:*:macos:*:* cpe:2.3:a:zoom:rooms_controller:*:*:*:*:*:windows:*:* cpe:2.3:a:zoom:workplace:*:*:*:*:*:iphone_os:*:* cpe:2.3:a:zoom:workplace_desktop:*:*:*:*:*:linux:*:* cpe:2.3:a:zoom:workplace_desktop:*:*:*:*:*:macos:*:* cpe:2.3:a:zoom:workplace_desktop:*:*:*:*:*:windows:*:* cpe:2.3:a:zoom:workplace_virtual_desktop_infrastructure:*:*:*:*:*:windows:*:* |
|
| Vendors & Products |
Zoom meeting Software Development Kit
Zoom rooms Zoom rooms Controller Zoom workplace Desktop Zoom workplace Virtual Desktop Infrastructure |
Fri, 12 Sep 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zoom
Zoom workplace Zoom workplace App Zoom zoom |
|
| Vendors & Products |
Zoom
Zoom workplace Zoom workplace App Zoom zoom |
Wed, 10 Sep 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Sep 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-site scripting in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network access. | |
| Title | Zoom Workplace Clients - Cross-site Scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Zoom
Published:
Updated: 2025-09-10T20:24:36.497Z
Reserved: 2025-06-04T22:48:18.920Z
Link: CVE-2025-49461
Updated: 2025-09-10T20:24:32.916Z
Status : Analyzed
Published: 2025-09-09T22:15:33.013
Modified: 2025-10-06T17:45:49.187
Link: CVE-2025-49461
No data.
OpenCVE Enrichment
Updated: 2025-09-12T09:11:40Z
EUVD