CVE-2025-46496
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-46496 is a Cross-site Scripting (XSS) vulnerability affecting the Mini twitter feed in Oniswap. An attacker can exploit this issue by injecting malicious scripts into the feed, which could then be executed in a user's browser when they view the affected page. This stored XSS vulnerability exists in the feed from an unknown version up to 3.0, potentially impacting numerous users. Successful exploitation could lead to unauthorized access to user data or sessions, as well as the ability to perform actions on behalf of the affected user. It is recommended that users and administrators update to the latest version of Oniswap's Mini twitter feed to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.