CVE-2025-46453: WordPress Zoho Creator Forms <= 1.0.5 - Cross Site Scripting (XSS) Vulnerability
Published Apr 24, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreatorTeam Zoho Creator Forms allows Stored XSS. This issue affects Zoho Creator Forms: from n/a through 1.0.5.
Affected Software
1 affected component
Zoho Creator Forms>=1.0.5
Event History
Apr 24, 2025
CVE Published
via MITRE·04:09 PM
Data Sourced
via MITRE·04:09 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Apr 14, 57299
Event
via FIRST·08:42 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-46453?
CVE-2025-46453 has a high severity rating due to its potential for stored cross-site scripting attacks.
2
How do I fix CVE-2025-46453?
To fix CVE-2025-46453, update Zoho Creator Forms to the latest version that addresses this vulnerability.
3
What type of vulnerability is CVE-2025-46453?
CVE-2025-46453 is classified as a stored cross-site scripting (XSS) vulnerability.
4
Which versions of Zoho Creator Forms are affected by CVE-2025-46453?
CVE-2025-46453 affects all versions of Zoho Creator Forms from n/a through 1.0.5.
5
What impact can CVE-2025-46453 have on users?
CVE-2025-46453 can lead to attackers executing malicious scripts in the context of other users, compromising their data and security.