Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18910 | CryptPad is a collaboration suite. Prior to version 2025.3.0, the "Link Bouncer" functionality attempts to filter javascript URIs to prevent Cross-Site Scripting (XSS), however this can be bypassed. There is an "early allow" code path that happens before the URI's protocol/scheme is checked, which a maliciously crafted URI can follow. This issue has been patched in version 2025.3.0. |
Mon, 11 Aug 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xwiki
Xwiki cryptpad |
|
| CPEs | cpe:2.3:a:xwiki:cryptpad:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xwiki
Xwiki cryptpad |
|
| Metrics |
cvssV3_1
|
Mon, 23 Jun 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 18 Jun 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CryptPad is a collaboration suite. Prior to version 2025.3.0, the "Link Bouncer" functionality attempts to filter javascript URIs to prevent Cross-Site Scripting (XSS), however this can be bypassed. There is an "early allow" code path that happens before the URI's protocol/scheme is checked, which a maliciously crafted URI can follow. This issue has been patched in version 2025.3.0. | |
| Title | CryptPad Dom-Based Cross-Site Scripting (XSS) Vulnerability | |
| Weaknesses | CWE-692 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-06-23T16:41:36.205Z
Reserved: 2025-06-06T15:44:21.556Z
Link: CVE-2025-49590
Updated: 2025-06-23T16:41:28.519Z
Status : Analyzed
Published: 2025-06-18T23:15:19.200
Modified: 2025-08-11T18:18:19.470
Link: CVE-2025-49590
No data.
OpenCVE Enrichment
No data.
EUVD