{"id":"CVE-2025-31626","title":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alisaleem252 Support Helpdesk Ticket System Lite ticket-help-desk-system-lite allows Reflected XSS.This issue affects Support Helpdesk …","summary":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alisaleem252 Support Helpdesk Ticket System Lite ticket-help-desk-system-lite allows Reflected XSS.This issue affects Support Helpdesk …","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L","cwe":["CWE-79"],"vendor":"Alisaleem252","product":"ticket-help-desk-system-lite","affected":["ticket-help-desk-system-lite <= 4.5.2"],"published":"2025-04-03","updated":"2026-10-06","sourceUpdated":"2026-10-06T16:17:04.187","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-31626","references":[{"url":"https://patchstack.com/database/wordpress/plugin/ticket-help-desk-system-lite/vulnerability/wordpress-support-helpdesk-ticket-system-lite-plugin-4-5-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve","label":"audit@patchstack.com"}],"tags":["nvd","cve.org"],"epss":0.00293,"epssPercentile":0.19952,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2025-04-03T14:19:32.964433Z"},"ingestedAt":"2026-10-06T16:04:04.486Z","slug":"CVE-2025-31626","body":"## Overview\n\nImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alisaleem252 Support Helpdesk Ticket System Lite ticket-help-desk-system-lite allows Reflected XSS.This issue affects Support Helpdesk Ticket System Lite: from n/a through 4.5.2.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}