Stored XSS Vulnerability in Quick Favicon by Robert Cummings
CVE-2025-53287
5.9MEDIUM
What is CVE-2025-53287?
A vulnerability has been identified in the Quick Favicon plugin developed by Robert Cummings, which allows for stored cross-site scripting (XSS). This issue arises due to improper sanitization of user inputs during web page generation, potentially allowing attackers to execute malicious scripts within the context of an affected website. The vulnerability impacts all versions of Quick Favicon up to 0.22.8, posing a risk to users' web environments. Ensuring proper input validation and sanitization can help mitigate this security threat.
Affected Version(s)
Quick Favicon <= 0.22.8