← All CVEs

CVE-2025-2703

medium · 6.8

The built-in XY Chart plugin is vulnerable to a DOM XSS vulnerability. A user with Editor permissions is able to modify such a panel in order to make it execute arbitrary JavaScript.

6.8
CVSS
16.2%
EPSS (exploit prob.)
97th
EPSS percentile
2025-04-23
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L

Weaknesses

CWE-79

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-2703