CVE-2025-11963
Reflected XSS in Saysis's StarCities
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
7th
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saysis Computer Systems Trade Ltd. Co. StarCities allows Reflected XSS. This issue affects StarCities: before 1.1.61.
| CWE | CWE-79 |
| Vendor | saysis computer systems trade ltd. co. |
| Product | starcities |
| Published | Nov 19, 2025 |
| Last Updated | Jun 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for saysis computer systems trade ltd. co. starcities
Be the first to know when new medium vulnerabilities affecting saysis computer systems trade ltd. co. starcities are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
Saysis Computer Systems Trade Ltd. Co. / StarCities
0 < 1.1.61
References
Credits
İbrahim YİĞİTSOY