CVE-2025-61949: Secuavail Logstare Collector
Medium severity, CVSS 4.8. EPSS: 0.2% chance of exploitation in the next 30 days.
LogStare Collector contains a stored cross-site scripting vulnerability in UserManagement. If crafted user information is stored, an arbitrary script may be executed on the web browser of the user who logs in to the product's management page.
Affected products
- Secuavail Logstare Collector: before 2.4.2 (fixed in 2.4.2)
Published 2025-11-21. Last modified 2026-06-17.