Home

Description

Cross Site Scripting vulnerability in Anycomment anycomment.io 0.4.4 allows a remote attacker to execute arbitrary code via the Anycomment comment section

PUBLISHED Reserved 2025-12-08 | Published 2026-01-15 | Updated 2026-01-15 | Assigner mitre

References

bdu.fstec.ru/vul/2023-08900

anycomment.io/site/changelog

cve.org (CVE-2025-67025)

nvd.nist.gov (CVE-2025-67025)

Download JSON