🔐 CVE Alert

CVE-2025-9208

UNKNOWN 0.0

Stored-XSS vulnerability discovered in OpenText WSM Management Server.

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Web Site Management Server allows Stored XSS. The vulnerability could execute malicious scripts on the client side when the download query parameter is removed from the file URL, allowing attackers to compromise user sessions and data. This issue affects Web Site Management Server: 16.7.X, 16.8, 16.8.1.

CWE CWE-79
Vendor opentext™
Product web site management server
Published Feb 19, 2026
Last Updated Feb 24, 2026
Stay Ahead of the Next One

Get instant alerts for opentext™ web site management server

Be the first to know when new unknown vulnerabilities affecting opentext™ web site management server are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

OpenText™ / Web Site Management Server
16.7.x 16.8 16.8.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
support.opentext.com: https://support.opentext.com/csm/en?id=ot_kb_unauthenticated&sysparm_article=KB0854844 github.com: https://github.com/MarioTesoro/vulnerability-research/blob/main/CVE-2025-9208/README.md

Credits

Murat Altindis