CVE-2025-61319

MEDIUM

yogeshojha/rengine < 2.2.0 - Stored Cross-Site Scripting in Vulnerabilities Module

Title source: llm
STIX 2.1

Description

ReNgine thru 2.2.0 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability in the Vulnerabilities module. When scanning a target with an XSS payload, the unsanitized payload is rendered in the ReNgine web UI, resulting in arbitrary JavaScript execution in the victim's browser. This can be abused to steal session cookies, perform unauthorized actions, or compromise the ReNgine administrator's account.

References (2)

Core 2

Scores

CVSS v3 6.1
EPSS 0.0026
EPSS Percentile 17.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
yogeshojha/rengine < 2.2.0
Published Oct 10, 2025
Tracked Since Feb 18, 2026