← back
CVE-2025-8550mediumCWE-79CWE-94

atjiu pybbs list cross site scripting

33Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 4.8epss 0.6%
from disclosure to weapon0 days
Published on NVDAug 5
1st PoCAug 5
exploitation probability
0.6%top 53% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
A vulnerability was found in atjiu pybbs up to 6.0.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/topic/list. The manipulation of the argument Username leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The patch is named 2fe4a51afbce0068c291bc1818bbc8f7f3b01a22. It is recommended to apply a patch to fix this issue.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
Affected products
atjiu · pybbs
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.