A cross-site scripting (XSS) vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to bypass security mechanisms or read application data.
We have already fixed the vulnerability in the following version:
QuMagie 2.8.1 and later
References
| Link | Resource |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-25-49 | Vendor Advisory |
Configurations
History
05 Jan 2026, 20:30
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
| References | () https://www.qnap.com/en/security-advisory/qsa-25-49 - Vendor Advisory | |
| CPE | cpe:2.3:a:qnap:qumagie:*:*:*:*:*:*:*:* | |
| First Time |
Qnap qumagie
Qnap |
02 Jan 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-02 15:16
Updated : 2026-01-05 20:30
NVD link : CVE-2025-62857
Mitre link : CVE-2025-62857
CVE.ORG link : CVE-2025-62857
JSON object : View
Products Affected
qnap
- qumagie
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
