← back
CVE-2025-2261

TIBCO BPM Enterprise XSS Vulnerability

CVSS 7 HIGHEPSS 0.3%CWE-79
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
21 May 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Stored XSS in TIBCO ActiveMatrix Administrator allows malicious data to appear to be part of the website and run within user's browser under the privileges of the web application.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →