CVE-2025-57393

High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.

A stored cross-site scripting (XSS) in Kissflow Work Platform Kissflow Application Versions 7337 Account v2.0 to v4.2vallows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.

Published 2025-10-01. Last modified 2026-07-05.