CVE-2025-51534: Craws Openatlas

High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.

A cross-site scripting (XSS) vulnerability in Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name field.

Affected products

  • Craws Openatlas: before 8.12.0 (fixed in 8.12.0)

Published 2025-08-04. Last modified 2026-06-17.