CVE-2025-1434: Areal Sas Topkapi Vision WEBSERV2

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

The Spreadsheet view is vulnerable to a XSS attack, where a remote unauthorised attacker can read a limited amount of values or DoS the affected spreadsheet. Disclosure of secrets or other system settings is not affected as well as other spreadsheets still work as expected.

Affected products

  • Areal Sas Topkapi Vision WEBSERV2: from 1.0.0, up to and including 6.2.5474

Published 2025-03-11. Last modified 2026-06-17.