AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-11966

MEDIUM · CVSS 6.4 EPSS 0.27%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-10-22 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.4. See the original NVD description below for full technical details.

CVE
CVE-2025-11966
Severity
MEDIUM
CVSS
6.4
EPSS
0.27%

Original NVD Description

In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], when "directory listing" is enabled, file and directory names are inserted into generated HTML without proper escaping in the href, title, and link attributes. An attacker who can create or rename files or directories within a served path can craft filenames containing malicious script or HTML content, leading to stored cross-site scripting (XSS) that executes in the context of users viewing the affected directory listing.

Related CVEs

Other vulnerabilities affecting the same vendor(s)