Cross-site Scripting Vulnerability in Ankara Hosting Website Design Software
CVE-2025-6397

8.6HIGH

Key Information:

Vendor
CVE Published:
3 February 2026

What is CVE-2025-6397?

A reflected cross-site scripting (XSS) vulnerability exists in Ankara Hosting's Website Design Software. This flaw allows attackers to inject malicious scripts into web pages viewed by other users, potentially compromising user data and session information. Despite early notification, the vendor has not responded to address this serious security issue. Users of the affected software versions are advised to take appropriate measures to mitigate the risks associated with this vulnerability.

Affected Version(s)

Website Software 0 <= 03022026

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aybike VURAL
.