CVE-2025-53883: Suse Container Suse Manager 5.0

Critical severity, CVSS 9.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability allows attackers to run arbitrary javascript via a reflected XSS issue in the search fields.This issue affects Container suse/manager/5.0/x86_64/server:latest: from ? before 5.0.28-150600.3.36.8; SUSE Manager Server LTS 4.3: from ? before 4.3.88-150400.3.113.5.

Affected products

  • Suse Container Suse Manager 5.0: before 5.0.28-150600.3.36.8 (fixed in 5.0.28-150600.3.36.8)
  • Suse Suse Manager Server LTS 4.3: before 4.3.88-150400.3.113.5 (fixed in 4.3.88-150400.3.113.5)

Published 2025-10-30. Last modified 2026-06-17.