CVE-2025-65237: Opencode Ussd Gateway
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
A reflected cross-site scripted (XSS) vulnerability in OpenCode Systems USSD Gateway OC Release: 5 allows attackers to execute arbitrary JavaScript in the context of a user's browser via injecting a crafted payload.
Affected products
- Opencode Ussd Gateway: version 6.13.11 only
Published 2025-11-26. Last modified 2026-06-17.