Stored Cross-Site Scripting Vulnerability in GroupSession by GroupSession Co.
CVE-2025-54407
What is CVE-2025-54407?
A stored cross-site scripting vulnerability was identified in multiple versions of GroupSession products. This flaw allows an attacker to execute arbitrary scripts in the web browser of users who access a specially crafted page or URL. Unpatched versions, including the Free edition and GroupSession byCloud and ZION, expose users to potential data theft and session hijacking risks. It is crucial for users to update to the latest versions to mitigate this security threat.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
GroupSession byCloud prior to ver5.3.3
GroupSession Free edition prior to ver5.3.0
GroupSession ZION prior to ver5.3.2
References
CVSS V4
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
