VYPR
Medium severity6.1NVD Advisory· Published Feb 16, 2026· Updated Jun 17, 2026

CVE-2025-59905

CVE-2025-59905

Description

Cross-Site Scripting (XSS) vulnerability reflected in Kubysoft, which occurs through multiple parameters within the endpoint ‘/node/kudaby/nodeFN/procedure’. This flaw allows the injection of arbitrary client-side scripts, which are immediately reflected in the HTTP response and executed in the victim's browser.

Affected products

3
  • Kubysoft/Kubysoft2 versions
    cpe:2.3:a:kubysoft:kubysoft:-:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:kubysoft:kubysoft:-:*:*:*:*:*:*:*
    • (no CPE)
  • Kubysoft/Kubysoftv5
    Range: All versions

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.