CVE-2025-13167: XSS
Published May 27, 2026
·Updated
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in contact functionality in Synology Contacts before 1.0.10-20659 allows remote authenticated users to read or write specific files containing non-sensitive information via unspecified vectors.
Affected Software
5 affected components
Synology Synology Contacts<1.0.10-20659
All of the following
Synology Contacts<1.0.10-20659
Any of the following
Synology Diskstation Manager=7.2.1
Synology Diskstation Manager=7.2.2
Synology Diskstation Manager=7.3
Event History
May 27, 2026
CVE Published
via MITRE·08:34 AM
Data Sourced
via MITRE·08:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-13167?
The severity of CVE-2025-13167 is medium with a CVSS score of 5.4.
2
How do I fix CVE-2025-13167?
To fix CVE-2025-13167, update Synology Contacts to version 1.0.10-20659 or higher.
3
What type of vulnerability is CVE-2025-13167?
CVE-2025-13167 is classified as a Cross-site Scripting (XSS) vulnerability.
4
Who can be affected by CVE-2025-13167?
Remote authenticated users can be affected by CVE-2025-13167.
5
What functionality is impacted by CVE-2025-13167?
CVE-2025-13167 impacts the contact functionality in Synology Contacts.