CVE Database
/

CVE-2025-59904

Back to search

CVE-2025-59904

Published: Feb 16, 2026

Modified: Feb 17, 2026

PUBLISHED

Description

Stored Cross-Site Scripting (XSS) vulnerability in Kubysoft, which is triggered through multiple parameters in the '/kForms/app' endpoint. This issue allows malicious scripts to be injected and executed persistently in the context of users accessing the affected resource.

VendorProductVersions

Kubysoft

Kubysoft

affected
All versions

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now