CVE-2025-4415: Piwik PRO - Moderately critical - Cross Site Scripting - SA-CONTRIB-2025-058
Published May 21, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Piwik PRO allows Cross-Site Scripting (XSS).This issue affects Piwik PRO: from 0.0.0 before 1.3.2.
Affected Software
2 affected components
Piwik PRO Piwik PRO>=0.0.0, <1.3.2
Matomo Piwik Pro Drupal<1.3.2
Event History
May 21, 2025
CVE Published
via MITRE·04:21 PM
Data Sourced
via MITRE·04:21 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-4415?
CVE-2025-4415 is classified as a moderate severity Cross-Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2025-4415?
To fix CVE-2025-4415, upgrade Piwik PRO to version 1.3.2 or later.
3
What software is affected by CVE-2025-4415?
CVE-2025-4415 affects Piwik PRO versions from 0.0.0 up to but not including 1.3.2.
4
What type of attack does CVE-2025-4415 enable?
CVE-2025-4415 enables attackers to perform Cross-Site Scripting (XSS) attacks.
5
When was CVE-2025-4415 disclosed?
CVE-2025-4415 was disclosed on the date it was assigned, though the exact date is not specified.