CVE-2025-27266

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Feb 24, 2025
CWE ID 79

Summary

CVE-2025-27266 is a Cross-site Scripting (XSS) vulnerability affecting Ignacio Perez Hover Image Button. The issue arises from improper neutralization of input during web page generation, allowing an attacker to inject malicious scripts into a webpage. As a result, an adversary can execute DOM-Based XSS attacks on unsuspecting users who visit the affected website. This vulnerability impacts versions of Hover Image Button from n/a through 1.1.2.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share