CVE-2025-55522: XSS
Published Aug 21, 2025
·Updated
Cross-site scripting (XSS) vulnerability in the component /common/reports of Akaunting v3.1.18 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the name parameter.
Affected Software
2 affected components
Akaunting Akaunting
Akaunting Akaunting>=3.0.4<=3.1.19
Event History
Aug 21, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-55522?
CVE-2025-55522 is classified as a high severity vulnerability due to its potential for XSS attacks.
2
How do I fix CVE-2025-55522?
To fix CVE-2025-55522, upgrade Akaunting to the latest version that addresses the XSS vulnerability.
3
What does CVE-2025-55522 exploit?
CVE-2025-55522 exploits a cross-site scripting vulnerability in the /common/reports component of Akaunting.
4
Which versions of Akaunting are affected by CVE-2025-55522?
CVE-2025-55522 affects Akaunting version 3.1.18.
5
What can attackers do using CVE-2025-55522?
Attackers can execute arbitrary web scripts or HTML by injecting a crafted payload into the name parameter due to CVE-2025-55522.