Cross-Site Scripting Vulnerability in CodegearThemes Designer Product
CVE-2025-23987
6.5MEDIUM
What is CVE-2025-23987?
The CodegearThemes Designer product has a vulnerability that allows for DOM-based Cross-Site Scripting (XSS) attacks due to improper neutralization of input during web page generation. This issue affects versions from n/a up to 1.6.0, enabling attackers to execute arbitrary JavaScript in users' browsers if they can craft a malicious input that bypasses the system's defenses.
Affected Version(s)
Designer <= 1.6.0