CVE-2025-67443
MEDIUMCVSS 6.1/10EPSS 0.16%
Last modified
CVE-2025-67443 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Schlix CMS before v2.2.9-5 is vulnerable to Cross Site Scripting (XSS). Due to lack of javascript sanitization in the login form, incorrect login attempts in logs are triggered as XSS in the admin panel.. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
Schlix CMS before v2.2.9-5 is vulnerable to Cross Site Scripting (XSS). Due to lack of javascript sanitization in the login form, incorrect login attempts in logs are triggered as XSS in the admin panel.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Schlix | Cms | < 2.2.9-5 |
References
- https://gist.github.com/akinerkisa/b22f4517a4011d049c5fc7fd3b29c9f2Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-67443?
Schlix CMS before v2.2.9-5 is vulnerable to Cross Site Scripting (XSS). Due to lack of javascript sanitization in the login form, incorrect login attempts in logs are triggered as XSS in the admin panel.
How severe is CVE-2025-67443?
CVE-2025-67443 has a CVSS score of 6.1/10 (MEDIUM severity). The EPSS model estimates a 0.16% probability of exploitation in the next 30 days.
How do I fix CVE-2025-67443?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-67433A heap buffer overflow in the processRequest function of Ope…7.5
- CVE-2025-67436Authenticated Remote Code Execution (RCE) in PluXml CMS 5.8.…6.5
- CVE-2025-67437Medical Management System a81df1ce700a9662cb136b27af47f4cbde…6.5
- CVE-2025-67438A Stored Cross-Site Scripting (XSS) vulnerability in Sync-in…6.1
- CVE-2025-6744The The Woodmart theme for WordPress is vulnerable to arbitr…7.3
- CVE-2025-67442EVE-NG 6.4.0-13-PRO is vulnerable to Directory Traversal. Th…7.6
- CVE-2025-67445TOTOLINK X5000R V9.1.0cu.2415_B20250515 contains a denial-of…7.5
- CVE-2025-67446Improper Authentication (Authentication Bypass) exists in Ne…9.8
- CVE-2025-67447The network diagnosis (ping) module in Neterbit NW-431F Rout…9.8
- CVE-2025-67448The SMS module in Neterbit NW-431F Router 20241014-IR03 and …7.1
- CVE-2025-6745The WoodMart plugin for WordPress is vulnerable to Informati…5.3
- CVE-2025-67450Due to insecure library loading in the Eaton UPS Companion s…7.8
Are you affected by CVE-2025-67443?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
