CVE-2025-67078

Cross site scripting (XSS) vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute arbitrary code via the notify parameter of the file controller used to display errors.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:agora-project:agora-project:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-15 16:16

Updated : 2026-01-21 14:42


NVD link : CVE-2025-67078

Mitre link : CVE-2025-67078

CVE.ORG link : CVE-2025-67078


JSON object : View

Products Affected

agora-project

  • agora-project
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')