CVE-2024-25573: Ping Identity Pingfederate

Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.

Unsanitized user-supplied data saved in the PingFederate Administrative Console could trigger the execution of JavaScript code in subsequent user processing.

Affected products

  • Ping Identity Pingfederate: from 12.1.0, up to and including 12.1.4; from 12.0.0, up to and including 12.0.6; from 11.3.0, up to and including 11.3.9; from 11.2.0, up to and including 11.2.10

Published 2025-06-15. Last modified 2026-06-17.