CVE-2025-21572: Oracle Opengrok

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

OpenGrok 1.13.25 has a reflected Cross-Site Scripting (XSS) issue when producing the history view page. This happens through improper handling of path segments. The application reflects unsanitized user input into the HTML output.

Affected products

  • Oracle Opengrok: version 1.13.25 only

Published 2025-05-02. Last modified 2026-06-17.