CVE-2025-23877
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-23877 is a Cross-site Scripting (XSS) vulnerability affecting the Nite Shortcodes web application from version n/a through 1.0. This issue arises due to improper neutralization of user input during the web page generation process. An attacker can exploit this flaw by injecting malicious code into a web page viewed by other users, potentially leading to unauthorized access to sensitive information or stealing user credentials. The vulnerability poses a significant risk to users and requires immediate mitigation measures, such as patching the affected software or implementing input validation techniques.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.