Vulnerabilities
CVE-2025-13488 - Nexus Repository 3 - Stored Cross-Site Scripting (XSS)
CVE ID : CVE-2025-13488 Published : Dec. 4, 2025, 6:16 p.m. | 32 minutes ago Description : Due to a regression introduced in version 3.83.0, a security header is no longer applied to certain user-uploaded content served from repositories. This may allow an authenticated attacker with repository upload privileges to exploit a stored cross-site scripting (XSS) vulnerability with user context. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Source: Telegram CVE Monitor