CVE-2025-11183: Qgis QWC2
Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.
Cross-Site Scripting vulnerability in attribute table in QGIS QWC2 <2025.08.14 allows an authorized attacker to plant arbitrary JavaScript code in the page
Affected products
- Qgis QWC2: before 2025.08.14 (fixed in 2025.08.14)
Published 2025-10-13. Last modified 2026-10-08.