CVE-2025-52180: Zucchetti Ad Hoc Infinity

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in Zucchetti Ad Hoc Infinity 4.2 and earlier allows remote unauthenticated attackers to inject arbitrary JavaScript via the pHtmlSource parameter of the /ahi/jsp/gsfr_feditorHTML.jsp?pHtmlSource endpoint.

Affected products

  • Zucchetti Ad Hoc Infinity: up to and including 4.2

Published 2025-10-30. Last modified 2026-06-17.