cleantalk
Vulnerabilities and Security Researches

Staff Directory Plugin: Company Directory, CVE-2025-25165

CVE, Research URL

CVE-2025-25165

Published on
Mar 03, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Staff Directory Plugin: Company Directory allows Stored XSS. This issue affects Staff Directory Plugin: Company Directory: from n/a through 4.3.
Affected versions
max 4.3.
Status
vulnerable