CVE-2025-62040

Severity
7.1HIGH
EPSS
0.0%
top 93.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 6

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YOP YOP Poll yop-poll.This issue affects YOP Poll: from n/a through <= 6.5.37.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:LExploitability: 2.8 | Impact: 3.7

Affected Packages1 packages

CVEListV5yop/yop_poll6.5.37

🔴Vulnerability Details

2
CVEList
WordPress YOP Poll plugin <= 6.5.37 - Cross Site Scripting (XSS) vulnerability2025-11-06
GHSA
GHSA-xhf8-58fx-m7x8: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YOP YOP Poll yop-poll2025-11-06
CVE-2025-62040 (HIGH CVSS 7.1) | Improper Neutralization of Input Du | cvebase.io