CVE-2025-14830 is a Cross-Site Scripting (XSS) vulnerability affecting JFrog Artifactory (Workers) versions from 7.94.0 up to, but not including, 7.117.10. This medium-severity vulnerability (CVSS 4.9) requires high privileges and no user interaction, potentially leading to high confidentiality impact. Currently, there is no known active exploitation, publicly available exploit code, or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| JFrog | Artifactory (Workers) | >= >=7.94.0, <= <7.117.10CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Improper Handling of Import Validation Mechanism Could Lead to DOM-based Cross-site Scripting
Jan 4, 2026JFrog Artifactory is vulnerable to improper handling of import Validation Mechanism which could lead to DOM-based cross-site scripting.
Jan 4, 2026JFrog Security Advisories