CVE-2025-21572: Oracle Opengrok
Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.
OpenGrok 1.13.25 has a reflected Cross-Site Scripting (XSS) issue when producing the history view page. This happens through improper handling of path segments. The application reflects unsanitized user input into the HTML output.
Affected products
- Oracle Opengrok: version 1.13.25 only
Published 2025-05-02. Last modified 2026-06-17.