---
id: CVE-2025-40681
title: >-
  Cross-site Scripting (XSS) vulnerability reflected in xCally's Omnichannel
  v3.30.1
summary: >-
  Cross-site Scripting (XSS) vulnerability reflected in xCally's Omnichannel
  v3.30.1. This vulnerability allowsan attacker to executed JavaScript code in
  the victim's browser by sending them a malicious URL using the
  'failureMessage' param…
severity: none
cwe:
  - CWE-79
published: '2025-11-13'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-40681'
references:
  - url: >-
      https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-xss-xcally-omnichannel
    label: cve-coordination@incibe.es
tags:
  - nvd
epss: 0.00306
epssPercentile: 0.21458
ingestedAt: '2026-10-07T21:54:15.030Z'
---

## Overview

Cross-site Scripting (XSS) vulnerability reflected in xCally's Omnichannel v3.30.1. This vulnerability allowsan attacker to executed JavaScript code in the victim's browser by sending them a malicious URL using the 'failureMessage' parameter in '/login'. This vulnerability can be exploited to steal sentitive user data, such as session cookies , or to perform actions on behalf of the user.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
