CVE-2025-62857

A cross-site scripting (XSS) vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following version: QuMagie 2.8.1 and later
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:qnap:qumagie:*:*:*:*:*:*:*:*

History

05 Jan 2026, 20:30

Type Values Removed Values Added
First Time Qnap qumagie
Qnap
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
References () https://www.qnap.com/en/security-advisory/qsa-25-49 - () https://www.qnap.com/en/security-advisory/qsa-25-49 - Vendor Advisory
CPE cpe:2.3:a:qnap:qumagie:*:*:*:*:*:*:*:*

02 Jan 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-02 15:16

Updated : 2026-01-05 20:30


NVD link : CVE-2025-62857

Mitre link : CVE-2025-62857

CVE.ORG link : CVE-2025-62857


JSON object : View

Products Affected

qnap

  • qumagie
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')