CVE-2026-25156 is a cross-site scripting (XSS) vulnerability affecting HotCRP conference review software versions from October 2025 through January 2026. The flaw allowed malicious HTML or SVG documents, uploaded to submission or comment fields, to execute in a user's browser with access to their HotCRP credentials, potentially leading to arbitrary API calls. Rated Medium (CVSS 6.3), this vulnerability requires user interaction (clicking a document link) and authenticated access to upload the malicious file. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.2CPE matchmatch criteria | cpe:2.3:a:hotcrp:hotcrp:3.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.