CVE-2025-25018: Elastic Kibana
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)
Affected products
- Elastic Kibana: from 7.0.0, before 8.18.8 (fixed in 8.18.8); from 8.19.0, before 8.19.5 (fixed in 8.19.5); from 9.0.0, before 9.0.8 (fixed in 9.0.8); from 9.1.0, before 9.1.5 (fixed in 9.1.5)
Published 2025-10-10. Last modified 2026-10-08.