CVE-2025-15223 describes a Cross-Site Scripting (XSS) vulnerability in Philipinho Simple-PHP-Blog, specifically within the /login.php file when manipulating the 'Username' argument. This medium-severity vulnerability (CVSS 6.1) can be exploited remotely with low attack complexity, potentially leading to limited impact on confidentiality and integrity. While public exploit details exist, there is no evidence of active exploitation, and community discussion and media coverage are minimal. The vendor has stated the product is for educational purposes only and does not provide specific version details due to its rolling release strategy.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2025-01-22CPE matchmatch criteria | cpe:2.3:a:philipinho:simple-php-blog:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.