Junglewise Threat Intelligence

CVE-2025-9969: Vizly Web Design Real Estate Packages reflected XSS

CVE-2025-9969 · Severity: high · CVSS 7.1 · Published 2025-09-19

Executive brief

Vizly Web Design Real Estate Packages, a software suite used for building and managing real estate websites, contains a security flaw that could allow attackers to manipulate website content. By tricking a user into clicking a malicious link, an attacker could steal sensitive session information or display fraudulent information to visitors. This could lead to unauthorized account access and damage to the business's reputation.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Vizly Web Design Real Estate Packages prior to version 5.1 due to improper neutralization of user-supplied input during web page generation. An unauthenticated remote attacker can exploit this by inducing a user to visit a specially crafted URL. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking (CAPEC-593), content spoofing, and unauthorized data access. The vulnerability is addressed in version 5.1.

Affected products

  • Vizly Web Design Real Estate Packages before 5.1

Timeline

  • 2025-09-19: disclosed
  • 2025-09-19: advisory

References