CVE-2025-15654
Fox-themes Prague
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fox-themes Prague allows Reflected XSS. This issue affects Prague: from n/a through 2.2.8.
- CVSS
- 7.1
- EPSS
- 0.15% 4.35% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.03