CVE-2025-10909: Mangati Novosga

Low severity, CVSS 2.4. EPSS: 0.3% chance of exploitation in the next 30 days.

A security flaw has been discovered in Mangati NovoSGA up to 2.2.9. The impacted element is an unknown function of the file /admin of the component SVG File Handler. Performing manipulation of the argument logoNavbar/logoLogin results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited.

Affected products

  • Mangati Novosga: version 2.2.0 only; version 2.2.1 only; version 2.2.2 only; version 2.2.3 only; version 2.2.4 only; version 2.2.5 only; …

Published 2025-09-24. Last modified 2026-06-17.