Stored Cross-Site Scripting Vulnerability in FileCodeBox by Vastsa
CVE-2025-51662

5.4MEDIUM

Key Information:

Vendor

Vastsa

Vendor
CVE Published:
19 November 2025

What is CVE-2025-51662?

A vulnerability in FileCodeBox allows for stored cross-site scripting (XSS), where insufficient input validation permits attackers to insert arbitrary JavaScript code into shared text 'codeboxes'. This malicious code executes automatically in the browsers of users accessing the compromised codebox via direct links or share codes, potentially leading to harmful outcomes such as data theft or session hijacking.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.