Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Diego León Casas

#49965of 53,633
4.8Total CVSS
Vulnerabilities · 1
PT-2025-5825
4.8
2025-02-06
Holded · Holded · CVE-2025-1076
Name of the Vulnerable Software and Affected Versions: Holded (affected versions not specified) Description: A Stored Cross-Site Scripting (Stored XSS) vulnerability has been found in the Holded application. This vulnerability could allow an attacker to store a JavaScript payload within the editable `name` and `icon` parameters of the Activities functionality. Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.