Medium severity5.4NVD Advisory· Published Oct 1, 2025· Updated Jun 17, 2026
CVE-2025-56514
CVE-2025-56514
Description
Cross Site Scripting (XSS) vulnerability in Fiora chat application 1.0.0 allows executes arbitrary JavaScript when malicious SVG files are rendered by other users.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Fiora/chat applicationdescription
- ghsa-coords
- cpe:2.3:a:suisuijiang:fiora:1.0.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
5- github.com/Kov404/CVE-2025-56514/tree/mainnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-hg3j-6pmh-mvjrghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-56514ghsaADVISORY
- fiora.suisuijiang.comghsaWEB
- fiora.suisuijiang.comnvdProduct
News mentions
0No linked articles in our index yet.