CVE-2025-48447 is a Cross-Site Scripting (XSS) vulnerability found in Drupal Lightgallery versions prior to 1.6.0, stemming from improper neutralization of input during web page generation. This vulnerability carries a CVSS score of 7.1 (HIGH), indicating a network-exploitable flaw with low privileges required and no user interaction, potentially leading to low integrity and high availability impacts. While no active exploits, Metasploit modules, or Nuclei templates are currently available, and community discussion and media coverage are minimal, organizations using affected Lightgallery versions should prioritize patching to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6.0CPE matchmatch criteria | cpe:2.3:a:lightgallery_project:lightgallery:*:*:*:*:*:drupal:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.