CVE-2025-22483: QNAP License Center
Medium severity, CVSS 4.8. EPSS: 0.2% chance of exploitation in the next 30 days.
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: License Center 1.8.51 and later License Center 1.9.51 and later
Affected products
- QNAP License Center: from 1.8.17, before 1.8.51 (fixed in 1.8.51); from 1.9.36, before 1.9.51 (fixed in 1.9.51)
Published 2025-08-29. Last modified 2026-06-17.