Cross-Site Scripting Vulnerability in Schneider Electric Products
CVE-2025-13902
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 10 March 2026
What is CVE-2025-13902?
A Cross-Site Scripting (XSS) vulnerability exists in various Schneider Electric products due to improper neutralization of input during the generation of web pages. This flaw allows authenticated attackers to craft malicious elements that, when hovered over by a victim, can prompt their browser to execute arbitrary JavaScript code. This potential exposure underscores the importance of securing web applications to prevent exploitation and protect user data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Modicon Controllers M241/M251 Versions prior to 5.4.13.12
Modicon Controllers M258/LMC058 All versions
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved