CVE-2025-13058 MEDIUM

CVE-2025-13058: soerennb eXtplorer Filename cross site scripting

Vendor Soerennb
Product eXtplorer
Weakness CWE-79 · XSS
Published November 12, 2025
Last update February 24, 2026

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X

What the vulnerability does

01Description

A security flaw has been discovered in soerennb eXtplorer up to 2.1.15. The affected element is an unknown function of the component Filename Handler. The manipulation results in cross site scripting. The attack may be launched remotely. The patch is identified as 002def70b985f7012586df2c44368845bf405ab3. Applying a patch is advised to resolve this issue.

Key dates

02Disclosure timeline

November 12, 2025 CVE published
February 24, 2026 Record updated