CVE-2025-55573

QuantumNous new-api v.0.8.5.2 is vulnerable to Cross Site Scripting (XSS).
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:newapi:new_api:*:*:*:*:*:*:*:*

History

15 Sep 2025, 19:49

Type Values Removed Values Added
Summary
  • (es) La nueva API v.0.8.5.2 de QuantumNous es vulnerable a cross-site scripting (XSS).
CPE cpe:2.3:a:newapi:new_api:*:*:*:*:*:*:*:*
References () https://github.com/QuantumNous/new-api - () https://github.com/QuantumNous/new-api - Product
References () https://github.com/zh0u9527/docs/blob/master/new-api-wp.md - () https://github.com/zh0u9527/docs/blob/master/new-api-wp.md - Exploit, Third Party Advisory
First Time Newapi
Newapi new Api

22 Aug 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-22 15:15

Updated : 2025-09-15 19:49


NVD link : CVE-2025-55573

Mitre link : CVE-2025-55573

CVE.ORG link : CVE-2025-55573


JSON object : View

Products Affected

newapi

  • new_api
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')