Sploitus

CVE-2025-61417

No indexed exploits for CVE-2025-61417 yet

Cross-Site Scripting (XSS) vulnerability exists in TastyIgniter 3.7.7, affecting the /admin/media_manager component. Attackers can upload a malicious SVG file containing JavaScript code. When an administrator previews the file, the code executes in their browser context, allowing the attacker to perform unauthorized actions such as modifying the admin account credentials.

Affected products
Tastyigniter
Tastyigniter
= 3.7.7
Fix
Available
CVSS 3.1
8.8 HIGH
EPSS
0.6% (44th percentile)
Weakness
CWE-434, CWE-79
NVD status
Analyzed
Published
2025-10-20
CVE-2025-61417 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-61417 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-61417 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.