PT-2025-38964 · Extendyourweb · Extendyourweb Horizontal Slider

Published

2025-09-22

·

Updated

2025-09-23

·

CVE-2025-58676

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions extendyourweb HORIZONTAL SLIDER versions through 2.4
Description A Cross-Site Request Forgery (CSRF) issue exists in extendyourweb HORIZONTAL SLIDER, which also allows Stored Cross-Site Scripting (XSS). The issue impacts the application's ability to properly validate requests, potentially allowing an attacker to perform actions on behalf of an authenticated user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Weakness Enumeration

Related Identifiers

CVE-2025-58676

Affected Products

Extendyourweb Horizontal Slider