PT-2025-24474 · Unknown · Category Icon

Drew / Mcdruid

·

Published

2025-06-09

·

Updated

2025-06-09

·

CVE-2025-31039

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Category Icon versions 1.0.2 and earlier
Description The issue is related to an Improper Restriction of XML External Entity Reference vulnerability in Category Icon, which allows XML Entity Linking.
Recommendations For Category Icon versions 1.0.2 and earlier, update to a version that fixes this issue, as the current version allows XML Entity Linking due to improper restriction of XML external entity references. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XXE

Weakness Enumeration

Related Identifiers

CVE-2025-31039

Affected Products

Category Icon