CVE-2025-25018: Elastic Kibana

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)

Affected products

  • Elastic Kibana: from 7.0.0, before 8.18.8 (fixed in 8.18.8); from 8.19.0, before 8.19.5 (fixed in 8.19.5); from 9.0.0, before 9.0.8 (fixed in 9.0.8); from 9.1.0, before 9.1.5 (fixed in 9.1.5)

Published 2025-10-10. Last modified 2026-10-08.