cleantalk
Vulnerabilities and Security Researches

CodeColorer, CVE-2025-68012

CVE, Research URL

CVE-2025-68012

Application

CodeColorer

Published on
Jan 22, 2026
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dmytro Shteflyuk CodeColorer codecolorer allows Stored XSS.This issue affects CodeColorer: from n/a through <= 0.10.1.
Affected versions
max 0.10.1.
Status
vulnerable