CVE-2025-62857

A cross-site scripting (XSS) vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following version: QuMagie 2.8.1 and later
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:qnap:qumagie:*:*:*:*:*:*:*:*

History

05 Jan 2026, 20:30

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
References () https://www.qnap.com/en/security-advisory/qsa-25-49 - () https://www.qnap.com/en/security-advisory/qsa-25-49 - Vendor Advisory
CPE cpe:2.3:a:qnap:qumagie:*:*:*:*:*:*:*:*
First Time Qnap qumagie
Qnap

02 Jan 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-02 15:16

Updated : 2026-01-05 20:30


NVD link : CVE-2025-62857

Mitre link : CVE-2025-62857

CVE.ORG link : CVE-2025-62857


JSON object : View

Products Affected

qnap

  • qumagie
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')