CVE-2025-46233
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2025-46233 is a Cross-site Scripting (XSS) vulnerability affecting Sirv CDN and Image Hosting. The flaw, which allows Stored XSS attacks, enables malicious actors to inject malicious scripts into Sirv's web pages. Users visiting affected pages may unknowingly execute these scripts, potentially leading to information theft, session hijacking, or other malicious activities. Sirv versions from n/a through 7.5.3 are reportedly vulnerable to this issue. Users are strongly advised to update to the latest version or contact their service provider to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.