CVE-2025-57393
the affected product
A stored cross-site scripting (XSS) in Kissflow Work Platform Kissflow Application Versions 7337 Account v2.0 to v4.2vallows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.
- CVSS
- 8.8
- EPSS
- 0.32% 24.1% percentile
- CISA KEV
- Not listed
- Published
- 2025.10.02