CVE-2025-67078

Cross site scripting (XSS) vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute arbitrary code via the notify parameter of the file controller used to display errors.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:agora-project:agora-project:*:*:*:*:*:*:*:*

History

21 Jan 2026, 14:42

Type Values Removed Values Added
CWE CWE-79
First Time Agora-project
Agora-project agora-project
CPE cpe:2.3:a:agora-project:agora-project:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
References () https://www.agora-project.net - () https://www.agora-project.net - Product
References () https://www.helx.io/blog/advisory-agora-project/ - () https://www.helx.io/blog/advisory-agora-project/ - Third Party Advisory

15 Jan 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-15 16:16

Updated : 2026-01-21 14:42


NVD link : CVE-2025-67078

Mitre link : CVE-2025-67078

CVE.ORG link : CVE-2025-67078


JSON object : View

Products Affected

agora-project

  • agora-project
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')