CVE-2025-59025
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
27/11/2025
Last modified:
27/11/2025
Description
Malicious e-mail content can be used to execute script code. Unintended actions can be executed in the context of the users account, including exfiltration of sensitive information. Sanitization has been updated to avoid such bypasses. No publicly available exploits are known
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM



