CVE-2025-56451

Cross site scripting vulnerability in seeyon Zhiyuan A8+ Collaborative Management Software 7.0 via the topValue parameter to the seeyon/main.do endpoint.
Configurations

Configuration 1 (hide)

cpe:2.3:a:seeyon:a8\+_collaborative_management:7.0:sp3:*:*:*:*:*:*

History

05 Feb 2026, 21:49

Type Values Removed Values Added
CPE cpe:2.3:a:seeyon:a8\+_collaborative_management:7.0:sp3:*:*:*:*:*:*
First Time Seeyon a8\+ Collaborative Management
Seeyon
References () https://gist.github.com/076w/b223381ba06b05845d919fb29619777b - () https://gist.github.com/076w/b223381ba06b05845d919fb29619777b - Third Party Advisory
References () https://www.yuque.com/076w/syst1m/zlp7c6hmowx6cg51?singleDoc - () https://www.yuque.com/076w/syst1m/zlp7c6hmowx6cg51?singleDoc - Exploit

16 Jan 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-16 22:16

Updated : 2026-02-05 21:49


NVD link : CVE-2025-56451

Mitre link : CVE-2025-56451

CVE.ORG link : CVE-2025-56451


JSON object : View

Products Affected

seeyon

  • a8\+_collaborative_management
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')