CVE-2025-15654: Fox-Themes Prague
High severity, CVSS 7.1. EPSS: 0.1% chance of exploitation in the next 30 days.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fox-themes Prague allows Reflected XSS. This issue affects Prague: from n/a through 2.2.8.
Affected products
- Fox-Themes Prague: up to and including 2.2.8
Published 2026-06-03. Last modified 2026-07-22.