CVE-2025-11183: Qgis QWC2

Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.

Cross-Site Scripting vulnerability in attribute table in QGIS QWC2 <2025.08.14 allows an authorized attacker to plant arbitrary JavaScript code in the page

Affected products

  • Qgis QWC2: before 2025.08.14 (fixed in 2025.08.14)

Published 2025-10-13. Last modified 2026-10-08.