CVE Database
/

CVE-2025-4379

Back to search

CVE-2025-4379

Published: May 23, 2025

Modified: May 23, 2025

PUBLISHED

Description

DobryCMS in versions 2.* and lower is vulnerable to Reflected Cross-Site Scripting (XSS). Improper input validation in szukaj parameter allows arbitrary JavaScript to be executed on victim's browser when specially crafted URL is opened. A hotfix for affected versions was released on 29.04.2025. It removes the vulnerability without incrementing the version.

VendorProductVersions

Studio Fabryka

DobryCMS

affected
0 - <= 2.*

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now