CVE-2025-68387
18.12.2025, 23:15
Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an unauthenticated user to embed a malicious script in content that will be served to web browsers causing cross-site scripting (XSS) (CAPEC-63) via a vulnerability a function handler in the Vega AST evaluator.| Vendor | Product | Version |
|---|---|---|
| elastic | kibana | 7.0.0 ≤ 𝑥 ≤ 7.17.29 |
| elastic | kibana | 8.0.0 ≤ 𝑥 < 8.19.9 |
| elastic | kibana | 9.0.0 ≤ 𝑥 < 9.1.9 |
| elastic | kibana | 9.2.0 ≤ 𝑥 < 9.2.3 |
𝑥
= Vulnerable software versions
Vulnerability Media Exposure