CVE-2025-52206: XSS
Published May 5, 2026
·Updated
ISPConfig 3.3.0 is vulnerable to Cross Site Scripting (XSS) via the system status webpage.
Affected Software
2 affected components
ISPConfig ISPConfig=3.3.0
ISPConfig ISPConfig=3.3.0
Event History
May 5, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-52206?
The severity of CVE-2025-52206 is rated as medium with a CVSS score of 4.7.
2
How do I fix CVE-2025-52206?
CVE-2025-52206 can be fixed by applying the available patch for ISPConfig 3.3.0.
3
What type of vulnerability is CVE-2025-52206?
CVE-2025-52206 is a Cross Site Scripting (XSS) vulnerability.
4
What is affected by CVE-2025-52206?
CVE-2025-52206 affects ISPConfig version 3.3.0 through the system status webpage.
5
When was CVE-2025-52206 published?
CVE-2025-52206 was published on May 5, 2026.