CVE-2025-28908

CVSS 3.1 Score 5.9 of 10 (medium)

Details

Published Mar 11, 2025
CWE ID 79

Summary

CVE-2025-28908 is a Cross-site Scripting (XSS) vulnerability affecting pipDisqus from versions n/a through 1.6. The flaw, named Improper Neutralization of Input During Web Page Generation, allows attackers to inject malicious scripts into web pages generated by pipDisqus, potentially stealing user information or taking over user sessions. This vulnerability could lead to serious security consequences if exploited, underscoring the importance of updating to the latest, secure version of pipDisqus.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share