CVE-2025-63499: Alinto Sogo

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter.

Affected products

  • Alinto Sogo: up to and including 5.12.4

Published 2025-12-04. Last modified 2026-06-17.