CVE-2025-26895
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Mar 15, 2025
CWE ID 79
Summary
CVE-2025-26895 is a Cross-site Scripting (XSS) vulnerability affecting the m1.DownloadList component of the maennchen1.de website. Specifically, this issue involves improper neutralization of user inputs during web page generation, which can lead to DOM-Based XSS attacks. These attacks allow malicious scripts to execute in a user's browser when they visit a compromised page, potentially leading to data theft or unauthorized access. The vulnerability has been identified in versions of m1.DownloadList from n/a through 0.19.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.