CVE Database
/

CVE-2025-1781

Back to search

CVE-2025-1781

Published: Mar 28, 2025

Modified: Mar 28, 2025

PUBLISHED

Description

There is a XXE in W3CSS Validator versions before cssval-20250226 that allows an attacker to use specially-crafted XML objects to coerce server-side request forgery (SSRF).  This could be exploited to read arbitrary local files if an attacker has access to exception messages.

VendorProductVersions

W3C

CSS Validator

affected
< cssval-20250226

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now