PT-2025-48354 · Retro · Retro

Published

2025-11-29

·

Updated

2026-01-29

·

CVE-2025-66036

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Retro versions prior to 2.4.7
Description Retro, an online platform for vintage collections, has a cross-site scripting (XSS) issue in the input handling component. This allows for potential malicious code execution through crafted input.
Recommendations Update to version 2.4.7 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-66036

Affected Products

Retro