Medium severity5.4NVD Advisory· Published Feb 19, 2026· Updated Jun 17, 2026
CVE-2025-9208
CVE-2025-9208
Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Web Site Management Server allows Stored XSS. The vulnerability could execute malicious scripts on the client side when the download query parameter is removed from the file URL, allowing attackers to compromise user sessions and data.
This issue affects Web Site Management Server: 16.7.X, 16.8, 16.8.1.
Affected products
3cpe:2.3:a:opentext:web_site_management_server:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:opentext:web_site_management_server:*:*:*:*:*:*:*:*range: <=16.8.1
- (no CPE)range: 16.7.X, 16.8, 16.8.1
- (no CPE)range: 16.7.x
Patches
Vulnerability mechanics
References
2- github.com/MarioTesoro/vulnerability-research/blob/main/CVE-2025-9208/README.mdnvdExploit
- support.opentext.com/csm/ennvdVendor Advisory
News mentions
0No linked articles in our index yet.