PT-2026-8327 · Kubysoft · Kubysoft

Published

2026-02-16

·

Updated

2026-03-09

·

CVE-2025-59904

CVSS v3.1

5.4

Medium

AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Kubysoft (affected versions not specified)
Description A stored Cross-Site Scripting (XSS) issue exists in Kubysoft. The issue is triggered through multiple parameters in the /kForms/app endpoint, allowing for the injection and persistent execution of malicious scripts within the context of users accessing the affected resource. The vulnerable parameters are not specified.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-59904

Affected Products

Kubysoft