Executive brief
PrivateBin vulnerable to malicious filename use for self-XSS / HTML injection locally for users
Affected products
- Packagist privatebin/privatebin
Junglewise Threat Intelligence
CVE-2025-64711 · Severity: low · CVSS 3.1 · Published 2025-11-14
Technologies: privatebin/privatebin (Packagist). Vendors: Packagist.
PrivateBin vulnerable to malicious filename use for self-XSS / HTML injection locally for users