CVE-2025-15355: Netvision Information Isoinsight
Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.
ISOinsight developed by NetVision Information has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.
Affected products
- Netvision Information Isoinsight: from 2.9.0, before 2.9.0.250911 (fixed in 2.9.0.250911); from 3.0.0, before 3.0.0.251127 (fixed in 3.0.0.251127)
Published 2025-12-30. Last modified 2026-10-07.