Executive brief
Citizen vulnerable to stored XSS in sticky header button messages
Affected products
- Packagist starcitizentools/citizen-skin
Junglewise Threat Intelligence
CVE-2025-62508 · Severity: low · CVSS 3.1 · Published 2025-10-20
Technologies: starcitizentools/citizen-skin (Packagist). Vendors: Packagist.
Citizen vulnerable to stored XSS in sticky header button messages