CVE-2025-51662

A stored cross-site scripting (XSS) vulnerability is found in the text sharing feature of FileCodeBox version 2.2 and earlier. Insufficient input validation allows attackers to inject arbitrary JavaScript code into shared text "codeboxes". The xss payload is automatically executed in the browsers of any users who try to access the infected codebox by clicking link or entering share code.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lanol:filecodebox:*:*:*:*:*:*:*:*

History

24 Nov 2025, 19:40

Type Values Removed Values Added
First Time Lanol filecodebox
Lanol
References () https://github.com/vastsa/FileCodeBox - () https://github.com/vastsa/FileCodeBox - Product
References () https://github.com/vastsa/FileCodeBox/issues/351 - () https://github.com/vastsa/FileCodeBox/issues/351 - Exploit, Issue Tracking
CPE cpe:2.3:a:lanol:filecodebox:*:*:*:*:*:*:*:*

20 Nov 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CWE CWE-79
References () https://github.com/vastsa/FileCodeBox/issues/351 - () https://github.com/vastsa/FileCodeBox/issues/351 -

19 Nov 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-19 20:15

Updated : 2025-11-24 19:40


NVD link : CVE-2025-51662

Mitre link : CVE-2025-51662

CVE.ORG link : CVE-2025-51662


JSON object : View

Products Affected

lanol

  • filecodebox
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')