CVE-2025-25134
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-25134 is a Cross-Site Scripting (XSS) vulnerability affecting the Not Found Theme Demo Bar. The issue stems from improper input neutralization during web page generation, enabling an attacker to inject malicious scripts into the bar. This impacts versions 1.6.3 and below of the Not Found Theme Demo Bar, potentially putting users at risk of data theft or unauthorized access. Attackers can exploit this flaw by tricking victims into visiting a malicious website or delivering the payload via phishing emails. Users are advised to update their Theme Demo Bar to the latest version or consider disabling the feature until a patch is available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.