CVE-2025-60948
Census CSWeb stored XSS
CVSS Score
4.6
EPSS Score
0.0%
EPSS Percentile
11th
Census CSWeb 8.0.1 allows stored cross-site scripting in user supplied fields. A remote, authenticated attacker could store malicious javascript that executes in a victim's browser. Fixed in 8.1.0 alpha.
| CWE | CWE-79 |
| Vendor | census |
| Product | csweb |
| Published | Mar 23, 2026 |
| Last Updated | Mar 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for census csweb
Be the first to know when new medium vulnerabilities affecting census csweb are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
Census / CSWeb
8.0.1 < 8.1.0 alpha
References
github.com: https://github.com/hx381/cspro-exploits github.com: https://github.com/csprousers/csweb/commit/eba0b59a243390a1a4f9524cce6dbc0314bf0d91 cve.org: https://www.cve.org/CVERecord?id=CVE-2025-60948 raw.githubusercontent.com: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-082-01.json