Medium severity6.1NVD Advisory· Published Dec 4, 2025· Updated Jun 17, 2026
CVE-2025-65516
CVE-2025-65516
Description
A stored cross-site scripting (XSS) vulnerability was discovered in Seafile Community Edition prior to version 13.0.12. When Seafile is configured with the Golang file server, an attacker can upload a crafted SVG file containing malicious JavaScript and share it using a public link. Opening the link triggers script execution in the victim's browser. This issue has been fixed in Seafile Community Edition 13.0.12.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:seafile:seafile_server:*:*:*:*:community:*:*:*+ 1 more
- cpe:2.3:a:seafile:seafile_server:*:*:*:*:community:*:*:*range: <13.0.12
- (no CPE)range: <13.0.12
- Seafile/Community Editiondescription
Patches
Vulnerability mechanics
References
2- gist.github.com/x0root/e5597622fede55b320d29a248dce01e6nvdThird Party Advisory
- manual.seafile.com/latest/changelog/server-changelog/nvdRelease Notes
News mentions
0No linked articles in our index yet.