CVE-2025-55579: XSS
Published Aug 29, 2025
·Updated
SolidInvoice version 2.3.7 is vulnerable to a Stored Cross-Site Scripting (XSS) issue in the Tax Rates functionality. The vulnerability is fixed in version 2.3.8.
Affected Software
2 affected components
SolidInvoice SolidInvoice<2.3.8
SolidInvoice SolidInvoice=2.3.7
Event History
Aug 29, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-55579?
CVE-2025-55579 is classified as a medium severity Cross Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2025-55579?
To fix CVE-2025-55579, upgrade to SolidInvoice version 2.3.8 or later.
3
What functionality is affected by CVE-2025-55579?
CVE-2025-55579 affects the Tax Rate functionality in SolidInvoice.
4
Which versions of SolidInvoice are vulnerable to CVE-2025-55579?
SolidInvoice versions prior to 2.3.8, specifically version 2.3.7, are vulnerable to CVE-2025-55579.
5
What type of vulnerability is CVE-2025-55579?
CVE-2025-55579 is a Cross Site Scripting (XSS) vulnerability.