High severity8.8NVD Advisory· Published Jun 25, 2025· Updated Apr 15, 2026
CVE-2025-5015
CVE-2025-5015
Description
A cross-site scripting vulnerability exists in the AccuWeather and Custom RSS widget that allows an unauthenticated user to replace the RSS feed URL with a malicious one.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.