CVE-2025-25905: 4pace Cadclick

High severity, CVSS 7.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Cross-Site Scripting (XSS) vulnerability in CADClick v1.13.0 and before allows remote attackers to inject arbitrary web script or HTML via the "tree" parameter.

Affected products

  • 4pace Cadclick: up to and including 1.13.0

Published 2025-06-25. Last modified 2026-06-17.