CVE-2025-31286: XSS
Published Apr 2, 2025
·Updated
An HTML injection vulnerability previously discovered in Trend Vision One could have allowed a malicious user to execute arbitrary code. Please note: this issue has already been addressed on the backend service and is no longer considered an active vulnerability.
Affected Software
2 affected components
Trend Vision One
trendmicro Trend Vision One
Event History
Apr 2, 2025
CVE Published
via MITRE·04:39 PM
Data Sourced
via MITRE·04:39 PM
DescriptionSeverity
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Jan 7, 57642
Event
via NVD·06:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-31286?
CVE-2025-31286 is classified as a medium severity vulnerability due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2025-31286?
CVE-2025-31286 has already been addressed by Trend on the backend service, so no further action is required.
3
What software is affected by CVE-2025-31286?
CVE-2025-31286 affects Trend Micro Vision One.
4
Can CVE-2025-31286 still be exploited?
CVE-2025-31286 is no longer considered an active vulnerability and cannot be exploited.
5
What type of vulnerability is CVE-2025-31286?
CVE-2025-31286 is an HTML injection vulnerability.