CVE-2025-46729

Source
https://cve.org/CVERecord?id=CVE-2025-46729
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-46729.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-46729
Aliases
  • GHSA-x3rx-6c2m-6vg9
Published
2025-05-12T10:37:04.011Z
Modified
2025-12-05T10:16:45.743387Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P CVSS Calculator
Summary
phpDVDProfiler Cross-site Scripting vulnerability
Details

julmud/phpDVDProfiler is an adoption of the defunct phpDVDProfiler project, which allows users to display on the web their DVD collections maintained with Invelos's DVDProfiler software. Starting in v20230807 and prior to v20250511, cross-site scripting in the search function. v_20250511 contains a patch for the issue.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/46xxx/CVE-2025-46729.json"
}
References

Affected packages

Git / github.com/julmud/phpdvdprofiler

Affected ranges

Type
GIT
Repo
https://github.com/julmud/phpdvdprofiler
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

Other
v_20191226
v_20191227
v_20191228
v_20191228_b
v_20191229
v_20200107
v_20200115
v_20200130
v_20230102
v_20230108
v_20230807

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-46729.json"