Cross-Site Scripting Issue in Splunk Enterprise and Splunk Cloud Platform
CVE-2025-20385
2.4LOW
Key Information:
- Vendor
Splunk
- Vendor
- CVE Published:
- 3 December 2025
What is CVE-2025-20385?
A cross-site scripting vulnerability exists in Splunk Enterprise and Splunk Cloud Platform versions preceding specified updates. Users with elevated privileges can manipulate navigation elements to inject malicious scripts, which execute in the browsers of unsuspecting users, potentially compromising user data and security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Splunk Cloud Platform 10.1.2507 < 10.1.2507.6
Splunk Cloud Platform 10.0.2503 < 10.0.2503.7
Splunk Cloud Platform 9.3.2411 < 9.3.2411.117