CVE-2025-23464

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Mar 3, 2025
CWE ID 79

Summary

CVE-2025-23464 is a Cross-site Scripting (XSS) vulnerability affecting Twitter's News Feed from an unknown version up to 1.1.1. Hackers can inject malicious scripts into web pages generated by the NotFound component, exploiting improper input neutralization. Users visiting affected pages could unintentionally execute these scripts, potentially leading to data theft or system compromise.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share