PT-2025-51177 · Unknown · Mayan Edms

Luca_Irinel

·

Published

2025-12-14

·

Updated

2026-03-05

·

CVE-2025-14691

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mayan EDMS versions up to 4.10.1
Description A cross-site scripting issue exists in Mayan EDMS. The issue is located in an unknown function within the /authentication/ component and can be exploited remotely. The exploit is publicly available.
Recommendations Upgrade to version 4.10.2 to resolve this issue.

Exploit

Fix

Code Injection

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-14691
GHSA-774Q-R975-VQWP
PYSEC-2025-134

Affected Products

Mayan Edms