{"id":"CVE-2025-9158","title":"The Request Tracker software is vulnerable to a Stored XSS vulnerability in calendar invitation parsing feature, which displays invitation data without HTML sanitization. XSS vulnerability allows an attacker to send a specifically crafte…","summary":"The Request Tracker software is vulnerable to a Stored XSS vulnerability in calendar invitation parsing feature, which displays invitation data without HTML sanitization. XSS vulnerability allows an attacker to send a specifically crafte…","severity":"none","cwe":["CWE-79"],"published":"2025-10-24","updated":"2026-10-08","sourceUpdated":"2026-10-08T11:10:00.250","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-9158","references":[{"url":"https://cert.pl/en/posts/2025/10/CVE-2025-9158/","label":"cvd@cert.pl"},{"url":"https://requesttracker.com/request-tracker/","label":"cvd@cert.pl"}],"tags":["nvd"],"epss":0.00447,"epssPercentile":0.36853,"ingestedAt":"2026-10-08T11:31:27.566Z","slug":"CVE-2025-9158","body":"## Overview\n\nThe Request Tracker software is vulnerable to a Stored XSS vulnerability in calendar invitation parsing feature, which displays invitation data without HTML sanitization. XSS vulnerability allows an attacker to send a specifically crafted e-mail enabling JavaScript code execution by displaying the ticket in the context of the logged-in user. \n\nThis vulnerability affects versions from 5.0.4 through 5.0.8 and from 6.0.0 through 6.0.1.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}