CVE-2025-30755: Oracle Opengrok
Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.
OpenGrok 1.14.1 has a reflected Cross-Site Scripting (XSS) issue when producing the cross reference page. This happens through improper handling of the revision parameter. The application reflects unsanitized user input into the HTML output.
Affected products
- Oracle Opengrok: version 1.14.1 only
Published 2025-09-19. Last modified 2026-06-17.