CVE-2025-30348: Qt

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

encodeText in QDom in Qt before 6.8.0 has a complex algorithm involving XML string copy and inline replacement of parts of a string (with relocation of later data).

Affected products

  • Qt Qt: before 5.15.19 (fixed in 5.15.19); from 6.0.0, before 6.5.9 (fixed in 6.5.9); from 6.6.0, before 6.8.0 (fixed in 6.8.0)

Published 2025-03-21. Last modified 2026-06-17.