CVE-2025-39514: WordPress Asgaros Forum plugin <= 3.2.1 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Asgaros Asgaros Forum allows Stored XSS. This issue affects Asgaros Forum: from n/a through 3.0.0.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Asgaros Asgaros Forum asgaros-forum allows Stored XSS.This issue affects Asgaros Forum: from n/a through <= 3.2.1.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39514?
The severity of CVE-2025-39514 is classified as a Stored Cross-Site Scripting (XSS) vulnerability.
How do I fix CVE-2025-39514?
To fix CVE-2025-39514, you should update Asgaros Forum to a version above 3.0.0.
What versions of Asgaros Forum are affected by CVE-2025-39514?
CVE-2025-39514 affects all versions of Asgaros Forum from n/a up to 3.0.0.
What type of vulnerability is CVE-2025-39514?
CVE-2025-39514 is categorized as an Improper Neutralization of Input During Web Page Generation leading to Cross-Site Scripting (XSS).
Can attackers exploit CVE-2025-39514 on my website?
Yes, attackers can exploit CVE-2025-39514 to execute malicious scripts on users' browsers if they interact with the affected Asgaros Forum.