CVE-2025-32540

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Apr 17, 2025
CWE ID 79

Summary

CVE-2025-32540 is a Cross-site Scripting (XSS) vulnerability affecting Feedify's Web Push Notifications. The issue, located within the feedify software version 2.4.5 and below, permits the injection of malicious scripts into web pages through improper neutralization of user input during the web page generation process. Successful exploitation of this vulnerability could lead to unintended execution of malicious code in a user's browser, potentially resulting in data theft, session hijacking, or other forms of unauthorized access. It is essential for users to update to the latest version of Feedify's Web Push Notifications to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share