CVE-2025-51662

A stored cross-site scripting (XSS) vulnerability is found in the text sharing feature of FileCodeBox version 2.2 and earlier. Insufficient input validation allows attackers to inject arbitrary JavaScript code into shared text "codeboxes". The xss payload is automatically executed in the browsers of any users who try to access the infected codebox by clicking link or entering share code.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lanol:filecodebox:*:*:*:*:*:*:*:*

History

24 Nov 2025, 19:40

Type Values Removed Values Added
References () https://github.com/vastsa/FileCodeBox - () https://github.com/vastsa/FileCodeBox - Product
References () https://github.com/vastsa/FileCodeBox/issues/351 - () https://github.com/vastsa/FileCodeBox/issues/351 - Exploit, Issue Tracking
CPE cpe:2.3:a:lanol:filecodebox:*:*:*:*:*:*:*:*
First Time Lanol filecodebox
Lanol

20 Nov 2025, 16:15

Type Values Removed Values Added
References () https://github.com/vastsa/FileCodeBox/issues/351 - () https://github.com/vastsa/FileCodeBox/issues/351 -
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

19 Nov 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-19 20:15

Updated : 2025-11-24 19:40


NVD link : CVE-2025-51662

Mitre link : CVE-2025-51662

CVE.ORG link : CVE-2025-51662


JSON object : View

Products Affected

lanol

  • filecodebox
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')