CVE-2025-36558: Kunbus GmbH Revolution Pi Pictory

Medium severity, CVSS 6.1. EPSS: 19.9% chance of exploitation in the next 30 days.

KUNBUS PiCtory version 2.11.1 and earlier are vulnerable to a cross-site-scripting attack via the sso_token used for authentication. If an attacker provides the user with a PiCtory URL containing an HTML script as an sso_token, that script will reply to the user and be executed.

Affected products

  • Kunbus GmbH Revolution Pi Pictory: up to and including 2.11.1

Published 2025-05-01. Last modified 2026-06-17.