CVE-2025-52344

Multiple Cross Site Scripting (XSS) vulnerabilities in input fields in Explorance Blue 8.1.2 allows attackers to inject arbitrary JavaScript code on the user's browser via the Group name and Project Description input fields.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:explorance:blue:8.1.2:*:*:*:*:*:*:*

History

05 Feb 2026, 17:03

Type Values Removed Values Added
CPE cpe:2.3:a:explorance:blue:8.1.2:*:*:*:*:*:*:*
First Time Explorance
Explorance blue
References () https://gist.github.com/SaraAlsaif/f363b307f29c865d499678eca3106b43 - () https://gist.github.com/SaraAlsaif/f363b307f29c865d499678eca3106b43 - Exploit, Mitigation, Third Party Advisory
References () https://www.explorance.com/products/blue - () https://www.explorance.com/products/blue - Product

15 Sep 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-15 18:15

Updated : 2026-02-05 17:03


NVD link : CVE-2025-52344

Mitre link : CVE-2025-52344

CVE.ORG link : CVE-2025-52344


JSON object : View

Products Affected

explorance

  • blue
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')