Unrated severityNVD Advisory· Published Feb 16, 2026· Updated Feb 17, 2026
Reflected Cross-Site Scripting (XSS) in Kubysoft
CVE-2025-59905
Description
Cross-Site Scripting (XSS) vulnerability reflected in Kubysoft, which occurs through multiple parameters within the endpoint ‘/node/kudaby/nodeFN/procedure’. This flaw allows the injection of arbitrary client-side scripts, which are immediately reflected in the HTTP response and executed in the victim's browser.
Affected products
1- Kubysoft/Kubysoftv5Range: All versions
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.