Low severity3.5NVD Advisory· Published Nov 19, 2025· Updated Jun 17, 2026
CVE-2025-13415
CVE-2025-13415
Description
A vulnerability was identified in icret EasyImages up to 2.8.6. This affects an unknown part of the file /app/upload.php of the component SVG Image Handler. The manipulation of the argument File leads to cross site scripting. It is possible to initiate the attack remotely.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<=2.8.6+ 1 more
- (no CPE)range: <=2.8.6
- (no CPE)range: 2.8.0
- cpe:2.3:a:easyimages2.0_project:easyimages2.0:*:*:*:*:*:*:*:*Range: <=2.8.6
Patches
Vulnerability mechanics
References
4- github.com/icret/EasyImages2.0/issues/260nvdExploitIssue TrackingThird Party Advisory
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdPermissions RequiredVDB Entry
News mentions
0No linked articles in our index yet.