Reflected Cross-Site Scripting Vulnerability in Nosto by Nosto Solutions
CVE-2025-40726
5.1MEDIUM
What is CVE-2025-40726?
A reflected Cross-Site Scripting (XSS) vulnerability exists in the search results page of Nosto, which can be exploited by attackers. By manipulating the 'q' GET request parameter, attackers can execute arbitrary code in the context of the user's session. This exposure can lead to unauthorized access and data theft, emphasizing the need for immediate remediation.
Affected Version(s)
Nosto All versions