---
id: CVE-2025-40725
title: Reflected Cross-Site Scripting (XSS) vulnerability in Azon Dominator
summary: >-
  Reflected Cross-Site Scripting (XSS) vulnerability in Azon Dominator. This
  vulnerability allows an attacker to execute JavaScript code in the victim's
  browser by sending them a malicious URL using the “q” parameter in /search via
  GET. Th…
severity: none
cwe:
  - CWE-79
published: '2025-09-10'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T00:10:00.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-40725'
references:
  - url: >-
      https://www.incibe.es/en/incibe-cert/notices/aviso/reflected-cross-site-scripting-xss-azon-dominator
    label: cve-coordination@incibe.es
tags:
  - nvd
epss: 0.00328
epssPercentile: 0.23258
ingestedAt: '2026-09-26T00:22:39.910Z'
---

## Overview

Reflected Cross-Site Scripting (XSS) vulnerability in Azon Dominator. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending them a malicious URL using the “q” parameter in /search via GET. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
