CVE-2025-44595: XSS
Published Sep 9, 2025
·Updated
Halo v2.20.17 and before is vulnerable to Cross Site Scripting (XSS) in /halohost/archives/{name}.
Affected Software
2 affected components
Halo Halo<2.20.17
Halo Halo<=2.20.17
Event History
Sep 9, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-44595?
CVE-2025-44595 is categorized as a medium severity vulnerability due to its potential for exploitation via Cross Site Scripting (XSS).
2
How do I fix CVE-2025-44595?
To fix CVE-2025-44595, upgrade to Halo v2.20.18 or later, which addresses the XSS vulnerability.
3
What software versions are affected by CVE-2025-44595?
CVE-2025-44595 affects Halo version 2.20.17 and earlier.
4
What type of vulnerability is CVE-2025-44595?
CVE-2025-44595 is a Cross Site Scripting (XSS) vulnerability.
5
Where is CVE-2025-44595 located within the application?
CVE-2025-44595 is located in the /halo_host/archives/{name} endpoint of the Halo application.