Home

Description

Seafile versions 11.0.18-Pro, 12.0.10, and 12.0.10-Pro are vulnerable to a stored Cross-Site Scripting (XSS) attack. An authenticated attacker can exploit this vulnerability by modifying their username to include a malicious XSS payload in notification and activities.

PUBLISHED Reserved 2025-04-22 | Published 2025-09-15 | Updated 2025-09-15 | Assigner mitre

References

plus.seafile.com/wiki/publish/seafile-wiki/txzO/

cve.org (CVE-2025-45091)

nvd.nist.gov (CVE-2025-45091)

Download JSON