Stored Cross-Site Scripting Vulnerability in ThinkDashboard by MatiasDesuu
CVE-2025-64177

5.4MEDIUM

Key Information:

Vendor
CVE Published:
6 November 2025

What is CVE-2025-64177?

ThinkDashboard, a self-hosted bookmark dashboard, has a vulnerability present in versions up to 0.6.7 that exposes users to stored Cross-Site Scripting (XSS) attacks. This occurs due to insufficient scheme filtering when clicking on malicious bookmarks. An attacker can exploit this weakness, leading to potential unauthorized actions being executed in the user's session. The issue has been resolved in version 0.6.8, so users are advised to update their installations to enhance security.

Affected Version(s)

ThinkDashboard < 0.6.8

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-64177 : Stored Cross-Site Scripting Vulnerability in ThinkDashboard by MatiasDesuu