CVE-2025-26555
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-26555 is a Cross-site Scripting (XSS) vulnerability affecting the Debug-Bar-Extender from version n/a through 0.5. This issue occurs due to improper neutralization of user input during web page generation, enabling attackers to inject malicious scripts and potentially steal user data or take control of their sessions. The vulnerability could be exploited through Reflected XSS attacks, posing a significant risk to users who visit maliciously crafted websites. It is recommended that users update to the latest version of Debug-Bar-Extender to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.