CVE-2025-40834: XSS
Published Nov 17, 2025
·Updated
A vulnerability has been identified in Mendix RichText (All versions >= V4.0.0 < V4.6.1). Affected widget does not properly neutralize the input. This could allow an attacker to execute cross-site scripting attacks.
Affected Software
1 affected component
Mendix RichText>=4.0.0<4.6.1
Event History
Nov 17, 2025
CVE Published
via MITRE·11:39 AM
Data Sourced
via MITRE·11:39 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-40834?
CVE-2025-40834 is classified as a moderate severity vulnerability due to potential cross-site scripting (XSS) attacks.
2
How do I fix CVE-2025-40834?
To fix CVE-2025-40834, upgrade Mendix RichText to a version greater than 4.6.1.
3
What are the affected versions of Mendix RichText for CVE-2025-40834?
CVE-2025-40834 affects all Mendix RichText versions from 4.0.0 to less than 4.6.1.
4
What is the risk of not addressing CVE-2025-40834?
Not addressing CVE-2025-40834 could allow attackers to execute cross-site scripting attacks, potentially compromising user data.
5
Who is the vendor for the software affected by CVE-2025-40834?
The vendor for the affected software in CVE-2025-40834 is Mendix.