CVE-2025-25018
10.10.2025, 10:15
Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)
| Vendor | Product | Version |
|---|---|---|
| elastic | kibana | 7.0.0 ≤ 𝑥 < 8.18.8 |
| elastic | kibana | 8.19.0 ≤ 𝑥 < 8.19.5 |
| elastic | kibana | 9.0.0 ≤ 𝑥 < 9.0.8 |
| elastic | kibana | 9.1.0 ≤ 𝑥 < 9.1.5 |
𝑥
= Vulnerable software versions