No advisories yet.
Solution
The vulnerability has been fixed by the Kubysoft team in the latest version of the software.
Workaround
No workaround given by the vendor.
Tue, 17 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Feb 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-Site Scripting (XSS) vulnerability reflected in Kubysoft, which occurs through multiple parameters within the endpoint ‘/node/kudaby/nodeFN/procedure’. This flaw allows the injection of arbitrary client-side scripts, which are immediately reflected in the HTTP response and executed in the victim's browser. | |
| Title | Reflected Cross-Site Scripting (XSS) in Kubysoft | |
| First Time appeared |
Kubysoft
Kubysoft kubysoft |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:kubysoft:kubysoft:all_versions:*:*:*:*:*:*:* | |
| Vendors & Products |
Kubysoft
Kubysoft kubysoft |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-02-17T16:44:06.603Z
Reserved: 2025-09-23T10:24:09.538Z
Link: CVE-2025-59905
Updated: 2026-02-17T16:44:02.887Z
Status : Awaiting Analysis
Published: 2026-02-16T10:16:07.390
Modified: 2026-02-18T17:52:22.253
Link: CVE-2025-59905
No data.
OpenCVE Enrichment
Updated: 2026-02-17T08:49:57Z