CVE-2021-25313Medium· 6.1▾ SunlitRancher Cross-site Scripting Vulnerability
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33.6 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
1.5%
Last analysed / modified upstream
A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rancher allows remote attackers to execute JavaScript via malicious links. This issue affects: SUSE Rancher Rancher versions prior to 2.5.6.
github.com/rancher/rancher >= 2.5.0, < 2.5.6github.com/rancher/rancher >= 2.4.0, < 2.4.14github.com/rancher/rancher < 2.3.11Upgrade to a patched release:
github.com/rancher/rancher 2.5.6github.com/rancher/rancher 2.4.14github.com/rancher/rancher 2.3.11Connected by shared product, vendor, weakness, or advisory.
CVE-2023-32196Critical· 9.1Rancher allows privilege escalation in Windows nodes due to Insecure Access Control Lists
CVE-2025-23387Medium· 5.3Rancher's SAML-based login via CLI can be denied by unauthenticated users
CVE-2026-25705High· 8.4Rancher Extensions have arbitrary file access via path traversal
CVE-2024-52281High· 8.9Rancher UI has Stored Cross-site Scripting vulnerability
GHSA-wm2r-rp98-8pmhLowExposure of SSH credentials in Rancher/Fleet
CVE-2021-25320Critical· 9.9Rancher cloud credentials can be used through proxy API by users without access