CVE-2025-11184: Qwc-Services Qwc-Registration-GUI

Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.

Cross-site scripting vulnerability in QGIS QWC2 Registration GUI <=v2025.03.31 allows an authorized attacker to plant arbitrary JavaScript code in the page

Affected products

  • Qwc-Services Qwc-Registration-GUI: up to and including v2025.03.31

Published 2025-10-13. Last modified 2026-10-08.