VYPR

appRain CMF

by Incibe.es

CVEs (1)

  • CVE-2025-41038MedSep 4, 2025
    risk 0.35cvss 5.4epss 0.00

    A vulnerability has been discovered in appRain CMF version 4.0.5, consisting of a stored authenticated XSS due to a lack of proper validation of user input, through the 'data[Group][name]' parameter in /apprain/admin/managegroup/add/.