CVE-2025-11966
 
Severity Score
2.3
*CVSS v4
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track*
*SSVC
Descriptions
In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], when "directory listing" is enabled, file and directory names are inserted into generated HTML without proper escaping in the href, title, and link attributes. An attacker who can create or rename files or directories within a served path can craft filenames containing malicious script or HTML content, leading to stored cross-site scripting (XSS) that executes in the context of users viewing the affected directory listing.
*Credits:
Sho Odagiri
CVSS Scores
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
System
Vulnerable | Subsequent
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track*
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2025-10-20 CVE Reserved
- 2025-10-22 CVE Published
- 2025-10-22 CVE Updated
- 2025-10-28 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CAPEC
References (1)
| URL | Date | SRC |
|---|
| URL | Date | SRC |
|---|
| URL | Date | SRC |
|---|
Affected Vendors, Products, and Versions
| Vendor | Product | Version | Other | Status | ||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
| Eclipse Foundation Search vendor "Eclipse Foundation" | Vert.x Search vendor "Eclipse Foundation" for product "Vert.x" | >= 4.0.0 < 4.5.22 Search vendor "Eclipse Foundation" for product "Vert.x" and version " >= 4.0.0 < 4.5.22" | en |
Affected
| ||||||
| Eclipse Foundation Search vendor "Eclipse Foundation" | Vert.x Search vendor "Eclipse Foundation" for product "Vert.x" | >= 5.0.0 < 5.0.5 Search vendor "Eclipse Foundation" for product "Vert.x" and version " >= 5.0.0 < 5.0.5" | en |
Affected
| ||||||
