Medium severity4.6NVD Advisory· Published Mar 23, 2026· Updated Jun 17, 2026
CVE-2025-60948
CVE-2025-60948
Description
Census CSWeb 8.0.1 allows stored cross-site scripting in user supplied fields. A remote, authenticated attacker could store malicious javascript that executes in a victim's browser. Fixed in 8.1.0 alpha.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4<8.1.0 alpha+ 1 more
- (no CPE)range: <8.1.0 alpha
- cpe:2.3:a:csprousers:csweb:8.0.1:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.