Back to search
CVE-2025-59904
Published: Feb 16, 2026
Modified: Feb 17, 2026
PUBLISHED
Description
Stored Cross-Site Scripting (XSS) vulnerability in Kubysoft, which is triggered through multiple parameters in the '/kForms/app' endpoint. This issue allows malicious scripts to be injected and executed persistently in the context of users accessing the affected resource.
| Vendor | Product | Versions |
|---|---|---|
Kubysoft | Kubysoft | affected All versions |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now