Medium severity6.1NVD Advisory· Published Feb 16, 2026· Updated Jun 17, 2026
CVE-2025-59905
CVE-2025-59905
Description
Cross-Site Scripting (XSS) vulnerability reflected in Kubysoft, which occurs through multiple parameters within the endpoint ‘/node/kudaby/nodeFN/procedure’. This flaw allows the injection of arbitrary client-side scripts, which are immediately reflected in the HTTP response and executed in the victim's browser.
Affected products
3- Kubysoft/Kubysoftv5Range: All versions
Patches
Vulnerability mechanics
References
1- www.incibe.es/en/incibe-cert/notices/aviso/reflected-cross-site-scripting-xss-kubysoftnvdThird Party Advisory
News mentions
0No linked articles in our index yet.