CVE-2025-26653: SAP SE SAP NetWeaver Application Server Abap Applications Based On SAP GUI For Html

Medium severity, CVSS 4.7. EPSS: 0.2% chance of exploitation in the next 30 days.

SAP NetWeaver Application Server ABAP does not sufficiently encode user-controlled inputs, leading to Stored Cross-Site Scripting (XSS) vulnerability. This enables an attacker, without requiring any privileges, to inject malicious JavaScript into a website. When a user visits the compromised page, the injected script gets executed, potentially compromising the confidentiality and integrity within the scope of the victim�s browser. Availability is not impacted.

Affected products

  • SAP SE SAP NetWeaver Application Server Abap Applications Based On SAP GUI For Html: version 7.22EXT only; version 7.53 only; version 7.54 only; version 7.77 only; version 7.89 only; version 7.93 only; …

Published 2025-04-08. Last modified 2026-06-17.