Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Reflected XSS in DSpace JSPUI Search Filtering |
Wed, 01 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lyrasis
Lyrasis dspace |
|
| CPEs | cpe:2.3:a:lyrasis:dspace:6.5:*:*:*:*:*:*:* | |
| Vendors & Products |
Lyrasis
Lyrasis dspace |
Tue, 31 Mar 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Reflected XSS in DSpace JSPUI Search Filtering |
Mon, 30 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 30 Mar 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Mon, 30 Mar 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dspace
Dspace jspui |
|
| Vendors & Products |
Dspace
Dspace jspui |
Fri, 27 Mar 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in DSpace JSPUI 6.5 within the search/discover filtering functionality. The vulnerability exists due to improper sanitization of user-supplied input via the filter_type_1 parameter. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-03-30T14:54:16.832Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-61190
Updated: 2026-03-30T14:50:27.122Z
Status : Analyzed
Published: 2026-03-27T15:16:45.750
Modified: 2026-03-31T21:11:17.520
Link: CVE-2025-61190
No data.
OpenCVE Enrichment
Updated: 2026-04-02T07:55:59Z