CVE-2025-25009: Kibana Cross-Site Scripting (XSS)
Published Oct 7, 2025
·Updated
Improper Neutralization of Input During Web Page Generation in Kibana can lead to Stored XSS via case file upload.
Affected Software
5 affected components
Elastic Kibana
Elastic Kibana>=7.0.0<8.18.8
Elastic Kibana>=8.19.0<8.19.5
Elastic Kibana>=9.0.0<9.0.8
Elastic Kibana>=9.1.0<9.1.5
Event History
Oct 7, 2025
CVE Published
via MITRE·01:59 PM
Data Sourced
via MITRE·01:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-25009?
CVE-2025-25009 has a high severity rating due to the potential for Stored XSS attacks.
2
How do I fix CVE-2025-25009?
To mitigate CVE-2025-25009, update Kibana to the latest version that includes the security patch issued by Elastic.
3
What type of vulnerability is CVE-2025-25009?
CVE-2025-25009 is categorized as an Improper Neutralization of Input During Web Page Generation vulnerability.
4
Can CVE-2025-25009 affect all versions of Kibana?
CVE-2025-25009 specifically affects certain versions of Kibana, so it is important to verify the version in use.
5
What is the impact of exploiting CVE-2025-25009?
Exploiting CVE-2025-25009 can lead to Stored XSS, allowing attackers to execute arbitrary scripts in the context of the affected user's session.