CVE-2025-13182

⚪ Do wiadomości

Wykorzystanie luki w pojoin h3blog umożliwia zdalne wykonanie ataku XSS.

CVSS
3.5
EPSS
0.3%
Exploit
poc
Vendor
h3blog
Opis źródłowy (NVD)

A vulnerability was identified in pojoin h3blog 1.0. The impacted element is an unknown function of the file /admin/cms/category/addtitle. The manipulation of the argument Title leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and might be used.

exploit xss Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS3.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2025-11-14 21:15:43 UTC
Ostatnia modyfikacja (NVD)2026-10-07 21:10:00 UTC
Referencje