Junglewise Threat Intelligence

CVE-2025-49578: starcitizentools/citizen-skin allows stored XSS in user registration date message

CVE-2025-49578 · Severity: low · CVSS 3.1 · Published 2025-06-13

Technologies: starcitizentools/citizen-skin (Packagist). Vendors: Packagist.

Executive brief

starcitizentools/citizen-skin allows stored XSS in user registration date message

Affected products

  • Packagist starcitizentools/citizen-skin

Related threats