CVE-2025-25018Cross-site Scripting in Kibana

Severity
5.4MEDIUMNVD
CNA8.7
EPSS
0.0%
top 92.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 10
Latest updateDec 15

Description

Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

NVDelastic/kibana7.0.08.18.8+3
CVEListV5elastic/kibana7.0.07.17.29+7

🔴Vulnerability Details

2
GHSA
GHSA-23vx-2j4v-jvhm: Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)2025-10-10
CVEList
Kibana Stored Cross-Site Scripting (XSS)2025-10-10

📋Vendor Advisories

2
Red Hat
kibana: Kibana: Cross-site Scripting (XSS) via integration package upload2025-12-15
Red Hat
Kibana: Kibana Stored Cross-Site Scripting (XSS)2025-10-10

🕵️Threat Intelligence

1
Wiz
CVE-2025-37732 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2025-25018 — Cross-site Scripting in Elastic Kibana | cvebase