Cross Site scripting vulnerability (XSS) in NetBox 4.3.5 "comment" field on object forms. An attacker can inject arbitrary HTML, which will be rendered in the web UI when viewed by other users. This could potentially lead to user interface redress attacks or be escalated to XSS in certain contexts.
References
Configurations
No configuration.
History
16 Mar 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-79 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
| References | () https://gist.github.com/MerttTuran/d94acff59816bfd9492d1a738e89ebb4 - |
16 Mar 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-16 16:16
Updated : 2026-03-17 14:20
NVD link : CVE-2025-57543
Mitre link : CVE-2025-57543
CVE.ORG link : CVE-2025-57543
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
