CVE-2025-9211: Otalio Ship Property Management System
Medium severity, CVSS 6.7. EPSS: 0.5% chance of exploitation in the next 30 days.
Unescaped stored values in application security page in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via persistent cross-site scripting
Affected products
- Otalio Ship Property Management System: before 2.22.0 (fixed in 2.22.0)
Published 2026-08-18. Last modified 2026-09-29.