CVE-2025-67078

Cross site scripting (XSS) vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute arbitrary code via the notify parameter of the file controller used to display errors.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:agora-project:agora-project:*:*:*:*:*:*:*:*

History

17 Jun 2026, 09:57

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de cross site scripting (XSS) en Omnispace Agora Project anterior a 25.10 que permite a los atacantes ejecutar código arbitrario a través del parámetro notify del controlador de archivos utilizado para mostrar errores.

21 Jan 2026, 14:42

Type Values Removed Values Added
References () https://www.agora-project.net - () https://www.agora-project.net - Product
References () https://www.helx.io/blog/advisory-agora-project/ - () https://www.helx.io/blog/advisory-agora-project/ - Third Party Advisory
CWE CWE-79
First Time Agora-project
Agora-project agora-project
CPE cpe:2.3:a:agora-project:agora-project:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

15 Jan 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-15 16:16

Updated : 2026-06-17 09:57


NVD link : CVE-2025-67078

Mitre link : CVE-2025-67078

CVE.ORG link : CVE-2025-67078


JSON object : View

Products Affected

agora-project

  • agora-project
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')