Junglewise Threat Intelligence

CVE-2025-8456: Kod8 Individual and SME Website reflected XSS

CVE-2025-8456 · Severity: high · CVSS 7.6 · Published 2026-02-03

Executive brief

Kod8 Individual and SME Website, a platform used by small businesses to manage their online presence, contains a security flaw that allows for reflected cross-site scripting. An attacker could trick a user into clicking a malicious link, allowing the attacker to execute unauthorized scripts in the user's browser session. This could lead to the theft of sensitive information, session hijacking, or unauthorized actions performed on behalf of the user.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Kod8 Software Technologies' Individual and SME Website software through version 03022026. The vulnerability is caused by improper neutralization of input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by sending a specially crafted link to a user; if the user clicks the link, the malicious script is executed within the context of the user's browser. This can result in session cookie theft, unauthorized API calls, or modification of the page content. As of the disclosure date, the vendor has not responded to reports of this vulnerability.

Affected products

  • Kod8 Software Technologies Trade Ltd. Co. Individual and SME Website through 03022026

Timeline

  • 2026-02-03: disclosed
  • 2026-02-03: advisory: Advisory published by TR-CERT (USOM)

References