{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-03T06:57:40.475","vulnerabilities":[{"cve":{"id":"CVE-2025-4951","sourceIdentifier":"cve@rapid7.com","published":"2025-05-20T09:15:21.207","lastModified":"2025-12-11T18:21:25.300","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Editions of Rapid7 AppSpider Pro before version 7.5.018 is vulnerable to a stored cross-site scripting vulnerability in the \"ScanName\" field.\nDespite the application preventing the inclusion of special characters within the \"ScanName\" field, this could be bypassed by modifying the configuration file directly.\n\nThis is fixed as of version 7.5.018"},{"lang":"es","value":"Las ediciones de Rapid7 AppSpider Pro anteriores a la versión 7.5.018 son afectados por una vulnerabilidad de cross-site scripting almacenado en el campo \"ScanName\". Aunque la aplicación impide la inclusión de caracteres especiales en el campo \"ScanName\", esto se puede evitar modificando directamente el archivo de configuración. Esto se ha corregido a partir de la versión 7.5.018."}],"metrics":{"cvssMetricV31":[{"source":"cve@rapid7.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":4.6,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.5,"impactScore":2.7}]},"weaknesses":[{"source":"cve@rapid7.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:rapid7:appspider_pro:*:*:*:*:*:*:*:*","versionEndExcluding":"7.5.018","matchCriteriaId":"EA39B4A4-2099-42B9-8F2D-98FB17B0A7F6"}]}]}],"references":[{"url":"https://docs.rapid7.com/release-notes/appspider/20250516/","source":"cve@rapid7.com","tags":["Release Notes"]}]}}]}