CVE-2025-25203HIGH 8.1EPSS p32.3%

CVE-2025-25203CVE-2025-25203

Description

CtrlPanel is open-source billing software for hosting providers. Prior to version 1.0, a Cross-Site Scripting (XSS) vulnerability exists in the `TicketsController` and `Moderation/TicketsController` due to insufficient input validation on the `priority` field during ticket creation and unsafe rendering of this field in the moderator panel. Version 1.0 contains a patch for the issue.

Scoring

CVSS 3.18.1 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS0.41% probability of exploitation · percentile 32.3% · 2026-06-19T12:03:05Z
Published2025-02-11
Last modified2026-04-15

Underlying weaknesses· 1

CWE-79

References

  1. https://github.com/Ctrlpanel-gg/panel/commit/393cbde662c7e54829e296eb5815794490d925c7
  2. https://github.com/Ctrlpanel-gg/panel/security/advisories/GHSA-2q43-grv2-jxwh

1

TypeTargetConfidenceTier
WeaknessImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting')cwe-790%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-34241
CVE
CVE-2026-34234
CVE
CVE-2026-34358
CVE
CVE-2026-23525
CVE
CVE-2025-65840
CVE
CWP Control Web Panel OS Command Injection Vulnerability
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.