CVE-2025-25009
07.10.2025, 14:15
Improper Neutralization of Input During Web Page Generation in Kibana can lead to Stored XSS via case file upload.
| Vendor | Product | Version |
|---|---|---|
| elastic | kibana | 7.0.0 ≤ 𝑥 < 8.18.8 |
| elastic | kibana | 8.19.0 ≤ 𝑥 < 8.19.5 |
| elastic | kibana | 9.0.0 ≤ 𝑥 < 9.0.8 |
| elastic | kibana | 9.1.0 ≤ 𝑥 < 9.1.5 |
𝑥
= Vulnerable software versions