CVE-2025-51962: Microstudio

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

A HTML Injection vulnerability in the comment section of the project page in MicroStudio 24.01.29 allows remote attackers to inject arbitrary web script or HTML via the text parameter of add_project_comment function.

Affected products

Published 2025-12-15. Last modified 2026-10-07.