CVE-2025-36750

ShineLan-X containsa stored cross site scripting (XSS) vulnerability in thePlant Name field. A HTML payloadwill be displayed on the plant management page via a direct post.This may allow attackers to force alegitimate users browsers JavaScript engine to run malicious code.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
UNKNOWN
---
DIVDCNA
---
---