🔐 CVE Alert

CVE-2025-13672

UNKNOWN 0.0

Reflected Cross-Site Scripting discovered in OpenText WSM Management Server.

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Web Site Management Server allows Reflected XSS. The vulnerability could allow injecting malicious JavaScript inside URL parameters that was then rendered with the preview of the page, so that malicious scripts could be executed on the client side. This issue affects Web Site Management Server: 16.7.0, 16.7.1.

CWE CWE-79
Vendor opentext™
Product web site management server
Published Feb 19, 2026
Last Updated Feb 24, 2026
Stay Ahead of the Next One

Get instant alerts for opentext™ web site management server

Be the first to know when new unknown vulnerabilities affecting opentext™ web site management server are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

OpenText™ / Web Site Management Server
16.7.0 16.7.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
support.opentext.com: https://support.opentext.com/csm/en?id=ot_kb_unauthenticated&sysparm_article=KB0854847 github.com: https://github.com/MarioTesoro/vulnerability-research/blob/main/CVE-2025-13672/README.md

Credits

Mario Tesoro