CVE-2025-49590
Severity CVSS v4.0:
LOW
Type:
Unavailable / Other
Publication date:
18/06/2025
Last modified:
11/08/2025
Description
CryptPad is a collaboration suite. Prior to version 2025.3.0, the "Link Bouncer" functionality attempts to filter javascript URIs to prevent Cross-Site Scripting (XSS), however this can be bypassed. There is an "early allow" code path that happens before the URI's protocol/scheme is checked, which a maliciously crafted URI can follow. This issue has been patched in version 2025.3.0.
Impact
Base Score 4.0
2.90
Severity 4.0
LOW
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:xwiki:cryptpad:*:*:*:*:*:*:*:* | 2025.3.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



