Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan James Zephyr Project Manager zephyr-project-manager allows Reflected XSS.This issue affects Zephyr Project Manager: from n/a through <= 3.3.101.

INFO

Published Date :

2025-04-17T15:47:41.166Z

Last Modified :

2026-04-01T15:51:01.606Z

Source :

Patchstack
AFFECTED PRODUCTS

The following products are affected by CVE-2025-32526 vulnerability.

Vendors Products
Zephyr-one
  • Zephyr Project Manager
REFERENCES

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact