CVE-2025-56537: XSS
Published Apr 29, 2026
·Updated
A stored cross-site scripting (XSS) vulnerability in opennebula v6.10.0.1 and fixed in v.7.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the virtual network template parameter.
Affected Software
2 affected components
OpenNebula OpenNebula=6.10.0.1
OpenNebula OpenNebula<7.0.0
Event History
Apr 29, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-56537?
The severity of CVE-2025-56537 is rated as medium with a score of 6.1.
2
How do I fix CVE-2025-56537?
To fix CVE-2025-56537, upgrade OpenNebula to version 7.0 or later.
3
What type of vulnerability is CVE-2025-56537?
CVE-2025-56537 is a stored cross-site scripting (XSS) vulnerability.
4
Which versions of OpenNebula are affected by CVE-2025-56537?
OpenNebula versions v6.10.0.1 and earlier are affected by CVE-2025-56537.
5
What can attackers do with CVE-2025-56537?
Attackers can execute arbitrary web scripts or HTML by injecting a crafted payload into the virtual network template parameter.