CVE-2025-52206: Ispconfig

Medium severity, CVSS 4.7. EPSS: 0.2% chance of exploitation in the next 30 days.

ISPConfig 3.3.0 is vulnerable to Cross Site Scripting (XSS) via the system status webpage.

Affected products

Published 2026-05-05. Last modified 2026-07-05.