Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-54812

21
FAUCET Score

CVE-2025-54812 is an Improper Output Neutralization vulnerability in Apache Log4cxx versions prior to 1.5.0, specifically impacting HTMLLayout. If untrusted data is used for logger names, an attacker could inject HTML or JavaScript into generated log files, potentially leading to Cross-Site Scripting (XSS) when a user views the logs. The CVSS score is 5.4 MEDIUM, indicating a network attack vector with low complexity, requiring user interaction, and resulting in low impact to confidentiality and integrity. While the EPSS and FAUCET scores are low, suggesting a low likelihood of exploitation, there is no known active exploitation, public exploit code, or significant community discussion beyond a single mention and article.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.5.0CPE matchmatch criteria
cpe:2.3:a:apache:log4cxx:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

2.1LOW

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
ACTIVE
VS Confidentiality
LOW
VS Integrity
LOW
VS Availability
NONE
SS Confidentiality
LOW
SS Integrity
LOW
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
1.16%
Probability of exploitation in next 30 days
EPSS Percentile
63.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0116 is in the 94th percentile among its peer group of 15,224 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

redhatCVE-2025-54812Low

log4cxx: Log4cxx HTMLLayout XSS Vulnerability

Aug 22, 2025

References

lists.debian.org / debian-lts-announce/2025/10/msg00002.html
openwall.com / lists/oss-security/2025/08/22/2
github.com / apache/logging-log4cxx/pull/509
Issue TrackingPatch
github.com / apache/logging-log4cxx/pull/514
Issue TrackingPatch
logging.apache.org / security.html
Vendor Advisory