CVE-2025-46516

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Apr 24, 2025
Updated: Apr 29, 2025
CWE ID 352

Summary

CVE-2025-46516 is a cross-site request forgery (CSRF) vulnerability affecting the Twitter Card Generator, version n/a through 1.0.5. An attacker could exploit this issue and perform stored XSS (Cross-Site Scripting) attacks on unsuspecting users. The CSRF technique allows an attacker to trick a user into making unwanted actions, such as modifying their account settings or stealing sensitive information. This vulnerability poses a significant risk, as it can lead to serious consequences, including data theft and unauthorized actions on the affected account. It is highly recommended that users update the Twitter Card Generator to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share