CVE-2025-51989High· 7.0▾ TwilightHTML injection vulnerability in the registration interface in Evolution Consulting Kft. HRmaster module v235 allows an attacker to inject HTML tags into the "keresztnév" (firstname) field, which will be sent out in an email resulting in …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 38.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
0.4% → 0.4%
HTML injection vulnerability in the registration interface in Evolution Consulting Kft. HRmaster module v235 allows an attacker to inject HTML tags into the "keresztnév" (firstname) field, which will be sent out in an email resulting in possible Phishing scenarios against any, previously not registered, email address.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-57440High· 7.5The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services
CVE-2026-91130Critical· 9.3Home Assistant is open source home automation software focused on local control and privacy
CVE-2026-68919High· 7.0GoCD is a continuous deliver server
CVE-2026-52741High· 7.5GoCD is a continuous deliver server
CVE-2026-73220NoneCVAT is an open source interactive video and image annotation tool for computer vision
CVE-2026-12751Medium· 5.4IBM Cloud Pak for Business Automation is vulnerable to HTML injection