PT-2025-41308 · Elastic · Kibana

Published

2025-10-08

·

Updated

2025-12-18

·

CVE-2025-25018

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Kibana versions 8.18.8, 8.19.5, 9.0.8, and 9.1.5
Description An issue exists in Kibana where improper neutralization of input during web page generation and improper validation of specified input types can lead to stored Cross-Site Scripting (XSS). This allows an attacker to inject malicious scripts into web pages viewed by other users.
Recommendations Update Kibana to version 8.18.8. Update Kibana to version 8.19.5. Update Kibana to version 9.0.8. Update Kibana to version 9.1.5.

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-ELK-2025-25018
BIT-KIBANA-2025-25018
CVE-2025-25018

Affected Products

Kibana