PT-2026-32327 · 1Panel Dev · Maxkb

·

CVE-2025-15632

·

Published

2026-04-13

·

Updated

2026-04-13

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions 1Panel-dev MaxKB versions prior to 2.5.0
Description An issue exists in the MdPreview component within the file 'ui/src/chat.ts'. This flaw allows a remote attacker to perform cross site scripting (XSS), which is a technique where malicious scripts are injected into trusted websites.
Recommendations Upgrade to version 2.5.0.

Exploit

Fix

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-15632

Affected Products

Maxkb