CVE-2025-67078

C

ross site scripting (XSS) vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute arbitrary code via the notify parameter of the file controller used to display errors.

References
Configurations

Configuration 1 (hide)

cpe:2.3:a:agora-project:agora-project:*:*:*:*:*:*:*:*

History

21 Jan 2026, 14:42

Type Values Removed Values Added
First Time Agora-project
Agora-project agora-project
References () https://www.agora-project.net - () https://www.agora-project.net - Product
References () https://www.helx.io/blog/advisory-agora-project/ - () https://www.helx.io/blog/advisory-agora-project/ - Third Party Advisory
CPE cpe:2.3:a:agora-project:agora-project:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CWE CWE-79

15 Jan 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-15 16:16

Updated : 2026-01-21 14:42


NVD link : CVE-2025-67078

Mitre link : CVE-2025-67078

CVE.ORG link : CVE-2025-67078


JSON object : View

Products Affected
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')