CVE-2025-53839
DRACOON Branding Service vulnerable to Cross-site Scripting
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
14 Jul 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
DRACOON is a file sharing service, and the DRACOON Branding Service allows customers to customize their DRACOON interface with their brand. Versions of the DRACOON Branding Service prior to 2.10.0 are vulnerable to cross-site scripting. Improper neutralization of input from administrative users could inject HTML code into the workflow for newly onboarded users. A fix was made available in version 2.10.0 and rolled out to the DRACOON service. DRACOON customers do not need to take action.
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N
Affected products
dracoon · security-advisoriesWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →