Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-25457 | UnoPim has Stored Cross-site Scripting vulnerability in user creation functionality |
Github GHSA |
GHSA-xr97-25v7-hc2q | UnoPim has Stored Cross-site Scripting vulnerability in user creation functionality |
Sat, 23 Aug 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Unopim
Unopim unopim |
|
| Vendors & Products |
Unopim
Unopim unopim |
Fri, 22 Aug 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Webkul
Webkul unopim |
|
| CPEs | cpe:2.3:a:webkul:unopim:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Webkul
Webkul unopim |
Thu, 21 Aug 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 21 Aug 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, UnoPim contains a stored cross-site scripting vulnerability via SVG MIME/sanitizer bypass in the /admin/settings/users/create endpoint. This vulnerability is fixed in 0.2.1. | |
| Title | UnoPim Stored XSS via SVG MIME/Sanitizer Bypass | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-08-21T19:58:34.442Z
Reserved: 2025-08-14T22:31:17.684Z
Link: CVE-2025-55742
Updated: 2025-08-21T19:58:29.420Z
Status : Analyzed
Published: 2025-08-21T16:15:34.280
Modified: 2025-08-22T21:55:09.320
Link: CVE-2025-55742
No data.
OpenCVE Enrichment
Updated: 2025-08-23T10:55:40Z
EUVD
Github GHSA