LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2025-56537

CVE-2025-56537 - Vulnerability Analysis

MediumCVSS: 6.1

Last Updated: April 29, 2026

OpenNebula - Stored XSS

Published: April 29, 2026Updated: April 29, 2026PoC AvailableRemote Exploitable

Overview

OpenNebula v6.10.0.1 contains a stored XSS caused by injection of crafted payload into the virtual network template parameter, letting attackers execute arbitrary web scripts or HTML, exploit requires no special privileges.

Severity & Score

Severity: Medium
CVSS Score: 6.1

Impact

Attackers can execute arbitrary scripts in users' browsers, potentially stealing session data or performing actions on behalf of users.

Mitigation

Upgrade to version 7.0 or later.

Details

CVE ID
CVE-2025-56537
Severity
Medium
CVSS Score
6.1
Type
stored_xss
Status
new

CWE

  • CWE-79

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N