PT-2025-37753 · Unknown · Seafile 12.0.10+2

Published

2025-09-15

·

Updated

2025-09-20

·

CVE-2025-45091

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Seafile versions 11.0.18-Pro Seafile versions 12.0.10 Seafile versions 12.0.10-Pro
Description Seafile is susceptible to a stored Cross-Site Scripting (XSS) attack. An authenticated attacker can exploit this issue by modifying their username to include a malicious XSS payload within notifications and activities.
Recommendations Seafile version 11.0.18-Pro: At the moment, there is no information about a newer version that contains a fix for this vulnerability. Seafile version 12.0.10: At the moment, there is no information about a newer version that contains a fix for this vulnerability. Seafile version 12.0.10-Pro: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-45091

Affected Products

Seafile 11.0.18-Pro
Seafile 12.0.10
Seafile 12.0.10-Pro