CVE-2025-1781
Severity CVSS v4.0:
HIGH
Type:
CWE-611
Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
28/03/2025
Last modified:
01/08/2025
Description
There is a XXE in W3CSS Validator versions before cssval-20250226 that allows an attacker to use specially-crafted XML objects to coerce server-side request forgery (SSRF). This could be exploited to read arbitrary local files if an attacker has access to exception messages.
Impact
Base Score 4.0
8.40
Severity 4.0
HIGH
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:w3:css_validator:*:*:*:*:*:*:*:* | 20250226 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



