CVE-2025-53121 describes multiple stored Cross-Site Scripting (XSS) vulnerabilities in OpenNMS Horizon versions 33.0.8 and earlier, specifically impacting unsanitized parameters across various nodes. This allows an authenticated attacker to inject malicious HTML or JavaScript into the database, which is then executed when other users view the affected pages. The vulnerability carries a CVSS score of 6.9 (Medium), indicating an attack vector requiring adjacent network access and user interaction, with high impact on confidentiality and integrity. There is currently no public exploit code available, nor is it listed on the CISA KEV catalog, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| The OpenNMS Group | Horizon | >= 33.0.8, < 33.1.6, 33.1.7CNA affecteddefault unaffected | |
| The OpenNMS Group | Meridian | >= 2023.1.20, < 2024.2.6, 2024.2.7, >= 2024.1.4, < 2024.2.6, 2024.2.7CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 1.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.