VYPR
Medium severity5.4NVD Advisory· Published Sep 4, 2025· Updated Jun 17, 2026

CVE-2025-41040

CVE-2025-41040

Description

A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[code]', 'data[lang][0][key]', 'data[lang][0][value]', 'data[lang][1][key]' and 'data[title]' parameters in /apprain/developer/language/lipsum.xml.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Apprain/Apprain3 versions
    cpe:2.3:a:apprain:apprain:4.0.5:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:apprain:apprain:4.0.5:*:*:*:*:*:*:*
    • (no CPE)range: = 4.0.5
    • (no CPE)range: 4.0.5

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.