CVE-2025-56536: XSS
Published Apr 29, 2026
·Updated
A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the user information parameter.
Affected Software
2 affected components
OpenNebula OpenNebula=6.10.0.1
OpenNebula OpenNebula<7.0.0
Event History
Apr 29, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-56536?
CVE-2025-56536 has a medium severity rating of 6.1 according to the CVSS scoring system.
2
How does CVE-2025-56536 affect OpenNebula?
CVE-2025-56536 allows attackers to execute arbitrary web scripts or HTML by injecting a crafted payload into the user information parameter in OpenNebula.
3
How can I fix CVE-2025-56536?
To fix CVE-2025-56536, update OpenNebula to a version that has patched the stored cross-site scripting vulnerability.
4
What type of vulnerability is CVE-2025-56536?
CVE-2025-56536 is a stored cross-site scripting (XSS) vulnerability.
5
What versions of OpenNebula are affected by CVE-2025-56536?
CVE-2025-56536 affects OpenNebula version 6.10.0.1.