Kubysoft operates a focused product line centered on a single offering where the durable vulnerability signal reflects application-layer input handling, with cross-site scripting forming the primary weakness class observed across its disclosures. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kubysoft over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-59905MEDIUM Cross-Site Scripting (XSS) vulnerability reflected in Kubysoft, which occurs through multiple parameters within the endpoint ‘/node/kudaby/nodeFN/procedure’. This flaw allows the i | Feb 16, 2026 | 6.1 | 21 | NO | NO |
CVE-2025-59904MEDIUM Stored Cross-Site Scripting (XSS) vulnerability in Kubysoft, which is triggered through multiple parameters in the '/kForms/app' endpoint. This issue allows malicious scripts to be | Feb 16, 2026 | 5.4 | 21 | NO | NO |
CVE-2025-59903MEDIUM Stored Cross-Site Scripting (XSS) vulnerability in Kubysoft, where uploaded SVG images are not properly sanitized. This allows attackers to embed malicious scripts within SVG files | Feb 16, 2026 | 5.4 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kubysoft.
Media articles that mention a CVE ID that affects a product developed by Kubysoft — matched by CVE ID, not by vendor name.