CVE-2025-25017: Elastic Kibana

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS)

Affected products

  • Elastic Kibana: from 7.0.0, before 8.18.8 (fixed in 8.18.8); from 8.19.0, before 8.19.4 (fixed in 8.19.4); from 9.0.0, before 9.0.7 (fixed in 9.0.7); from 9.1.0, before 9.1.4 (fixed in 9.1.4)

Published 2025-10-10. Last modified 2026-10-08.