Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-43717

16
FAUCET Score

CVE-2025-43717 describes a Cross-Site Scripting (XSS) vulnerability in PEAR HTTP_Request2 versions prior to 2.7.0, specifically within test files like getparameters.php and postparameters.php, which improperly reflect user-supplied GET or POST parameters. This medium-severity vulnerability (CVSS 5.4) has a network attack vector and high attack complexity, potentially leading to limited confidentiality and integrity impacts. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, and it is not listed in CISA's KEV catalog.

Impacted Technologies

VendorProductVersion(s)CPE
AvbHTTP Request2
>= 0, < 2.7.0CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

5.4MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.32%
Probability of exploitation in next 30 days
EPSS Percentile
23.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0032 is in the 3rd percentile among its peer group of 19,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

composerpatch availablevia ghsa
Product: pear/http_request2Fixed in: 2.7.0

Vendor Advisories (1)

composerGHSA-w7gh-f2fm-9q8rmedium

PEAR HTTP_Request2 vulnerable to Cross-site Scripting

Apr 17, 2025

References

github.com / pear/HTTP_Request2/blob/b1c61b71128045734d757c4d3d436457ace80ea7/package.xml
github.com / pear/HTTP_Request2/commit/07925aa77e441dba0ff0fa973a09802729cb838f
github.com / pear/HTTP_Request2/commit/265e05f9e08a28a38a57219516a8e4e2dfdbb147
github.com / pear/HTTP_Request2/compare/v2.6.0...v2.7.0