CVE-2025-32134
CVSS 3.1 Score 5.9 of 10 (medium)
Details
Summary
CVE-2025-32134 represents a Cross-site Scripting (XSS) vulnerability in KaizenCoders URL Shortify. Affecting versions from n/a to 1.10.4, this issue permits an attacker to inject malicious code into web pages generated by the URL Shortify software. By exploiting this Improper Neutralization of Input vulnerability, an attacker can execute scripts in users' browsers, potentially gaining unauthorized access to sensitive information, and performing actions on behalf of the user. This poses a significant risk to users, emphasizing the importance of patching affected installations promptly.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.