CVE-2025-8695
Last modified
CVE-2025-8695 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Netcad NetGIS Server allows Reflected XSS. This issue affects NetGIS Server: from 5.2.4 through 22.08.2025.. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Netcad NetGIS Server allows Reflected XSS. This issue affects NetGIS Server: from 5.2.4 through 22.08.2025.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-8695?
How severe is CVE-2025-8695?
How do I fix CVE-2025-8695?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-8688The Inline Stock Quotes plugin for WordPress is vulnerable t…6.4
- CVE-2025-8689The Elements Plus! plugin for WordPress is vulnerable to Sto…6.4
- CVE-2025-8690The Simple Responsive Slider plugin for WordPress is vulnera…6.4
- CVE-2025-8691The WP Scriptcase plugin for WordPress is vulnerable to Stor…6.4
- CVE-2025-8692The Coupon API plugin for WordPress is vulnerable to SQL Inj…4.9
- CVE-2025-8693A post-authentication command injection vulnerability in the…8.8
- CVE-2025-8696If an unauthenticated user sends a large amount of data to t…7.5
- CVE-2025-8697A vulnerability was found in agentUniverse up to 0.0.18 and …6.3
- CVE-2025-8698A vulnerability was found in Open5GS up to 2.7.5. It has bee…3.3
- CVE-2025-8699Some "Stored Value" Unattended Payment Solutions of KioSoft …9.1
- CVE-2025-8700Invoice Ninja's configuration on macOS, specifically the pre…4.8
- CVE-2025-8701A vulnerability was found in Wanzhou WOES Intelligent Optimi…8.8
Are you affected by CVE-2025-8695?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
