CVE-2025-25247: Apache Felix Webconsole
Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix Webconsole. This issue affects Apache Felix Webconsole 4.x up to 4.9.8 and 5.x up to 5.0.8. Users are recommended to upgrade to version 4.9.10 or 5.0.10 or higher, which fixes the issue.
Affected products
- Apache Felix Webconsole: from 4.0.0, before 4.9.10 (fixed in 4.9.10); from 5.0.0, before 5.0.10 (fixed in 5.0.10)
Published 2025-02-10. Last modified 2026-06-17.