CVE-2025-56535: XSS
Published Apr 29, 2026
·Updated
A cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the zone attribute parameter.
Affected Software
2 affected components
OpenNebula OpenNebula=6.10.0.1
OpenNebula OpenNebula<7.0.0
Event History
Apr 29, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-56535?
CVE-2025-56535 has a medium severity score of 6.1 according to the CVSS 3.1 rating.
2
What type of vulnerability is CVE-2025-56535?
CVE-2025-56535 is classified as a cross-site scripting (XSS) vulnerability.
3
How can I exploit CVE-2025-56535?
An attacker can exploit CVE-2025-56535 by injecting a crafted payload into the zone attribute parameter to execute arbitrary web scripts or HTML.
4
How do I fix CVE-2025-56535?
To mitigate CVE-2025-56535, update to the latest version of OpenNebula where the vulnerability is addressed.
5
What impact does CVE-2025-56535 have?
Exploitation of CVE-2025-56535 can lead to the execution of arbitrary web scripts, potentially compromising user data and security.