cbcvebase.
CVE-2025-53883
published 2025-10-30

CVE-2025-53883: A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability allows attackers to run arbitrary javascript via a reflected XSS…

PriorityP342critical9.3CVSS 4.0
AVNACLATNPRLUIPVCHVIHVANSCHSIHSAHEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.27%
19.4th percentile
A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability allows attackers to run arbitrary javascript via a reflected XSS issue in the search fields.This issue affects Container suse/manager/5.0/x86_64/server:latest: from ? before 5.0.28-150600.3.36.8; SUSE Manager Server LTS 4.3: from ? before 4.3.88-150400.3.113.5.

Affected

2 ranges
VendorProductVersion rangeFixed in
susecontainer_suse_manager_5.0< 5.0.28-150600.3.36.85.0.28-150600.3.36.8
susesuse_manager_server_lts_4.3< 4.3.88-150400.3.113.54.3.88-150400.3.113.5
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.