Sploitus

CVE-2025-68387

No indexed exploits for CVE-2025-68387 yet

Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an unauthenticated user to embed a malicious script in content that will be served to web browsers causing cross-site scripting (XSS) (CAPEC-63) via a vulnerability a function handler in the Vega AST evaluator.

Affected products
Kibana, Red Os, Vega Ast Evaluator
Elastic Kibana
≤ 7.17.29, 8.19.9, 9.1.9, 9.2.3
CVSS 3.1
6.1 MEDIUM
EPSS
0.2% (9th percentile)
Weakness
CWE-79
NVD status
Analyzed
Published
2025-12-18
Attack patterns
CAPEC-63
CVE-2025-68387 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-68387 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-68387 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.