Medium severity6.1NVD Advisory· Published May 7, 2025· Updated Jun 17, 2026
CVE-2025-29746
CVE-2025-29746
Description
Cross Site Scripting vulnerability in Koillection v.1.6.10 allows a remote attacker to escalate privileges via the collection, Wishlist and album components
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
koillection/koillectionPackagist | < 1.6.12 | 1.6.12 |
Affected products
2Patches
Vulnerability mechanics
References
6- gist.github.com/unklerunkle/73e2ab58d1a5b9129be5de55765ea4fenvdExploitThird Party AdvisoryWEB
- github.com/benjaminjonard/koillection/issues/1329nvdExploitIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-fxvx-gfmr-5xfjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-29746ghsaADVISORY
- github.com/benjaminjonard/koillection/releases/tag/1.6.11ghsaWEB
- github.com/benjaminjonard/koillection/releases/tag/1.6.12ghsaWEB
News mentions
0No linked articles in our index yet.