cbcvebase.
CVE-2025-11450
published 2025-10-10

CVE-2025-11450: ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could result in…

PriorityP429medium5.3CVSS 4.0
AVNACLATNPRNUIPVCNVINVANSCNSILSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.32%
24.1th percentile
ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could result in arbitrary code being executed within the browsers of ServiceNow users who click on a specially crafted link. ServiceNow has addressed this vulnerability by deploying a relevant security update to the majority of hosted instances. Relevant security updates also have been provided to ServiceNow self-hosted customers, partners, and hosted customers with unique configurations. Further, the vulnerability is addressed in the listed patches and hot fixes. We recommend customers promptly apply appropriate updates or upgrade if they have not already done so.

Affected

10 ranges
VendorProductVersion rangeFixed in
servicenowservicenow_ai_platform< Washington DC Patch 10 Hot Fix 7bWashington DC Patch 10 Hot Fix 7b
servicenowservicenow_ai_platform< Xanadu Patch 10 Hot Fix 1aXanadu Patch 10 Hot Fix 1a
servicenowservicenow_ai_platform< Xanadu Patch 11Xanadu Patch 11
servicenowservicenow_ai_platform< Yokohama Patch 7 Hot Fix 2aYokohama Patch 7 Hot Fix 2a
servicenowservicenow_ai_platform< Yokohama Patch 8Yokohama Patch 8
servicenowservicenow_ai_platform< Yokohama Patch 9Yokohama Patch 9
servicenowservicenow_ai_platform< Zurich Patch 1 Hot Fix 1aZurich Patch 1 Hot Fix 1a
servicenowservicenow_ai_platform< Zurich Patch 2Zurich Patch 2
servicenowservicenow_ai_platform< Zurich Patch 3Zurich Patch 3
servicenowservicenow_ai_platform< Australia General Availability (GA)Australia General Availability (GA)
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.