CVE-2025-40727

Publication date

2025-06-16 08:20:30

Family

INCIBE

State

PUBLISHED

Description

A Reflected Cross Site Scripting (XSS) vulnerability was found in /search in Phoenix Site CMS from Phoenix, which allows remote attackers to execute arbitrary code via s GET parameter.