CVE-2025-29526
Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.
A Cross-Site Scripting (XSS) vulnerability in the search function of Q4 Inc Investor Relations Platform v5.147.1.2 allows attackers to execute arbitrary Javascript via injecting a crafted payload into the SearchTerm parameter.
Published 2025-04-23. Last modified 2026-06-17.