PT-2026-32327 · 1Panel Dev · Maxkb

Ana10Gy

·

Published

2026-04-13

·

Updated

2026-04-13

·

CVE-2025-15632

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions 1Panel-dev MaxKB versions prior to 2.5.0
Description An issue exists in the MdPreview component within the file 'ui/src/chat.ts'. This flaw allows a remote attacker to perform cross site scripting (XSS), which is a technique where malicious scripts are injected into trusted websites.
Recommendations Upgrade to version 2.5.0.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-15632

Affected Products

Maxkb