CVE-2025-3261 - Stored Cross-Site Scripting (XSS) in ThingsBoard

CVE-2025-3261 - Stored Cross-Site Scripting (XSS) in ThingsBoard

CVE ID : CVE-2025-3261 Published : Nov. 27, 2025, 6:15 p.m. | 1 hour, 43 minutes ago Description : ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the

CVE Details

Published
Nov. 27, 2025

Source: Telegram CVE Monitor