Vulnerability Details CVE-2025-27867
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Felix HTTP Webconsole Plugin.
This issue affects Apache Felix HTTP Webconsole Plugin: from Version 1.X through 1.2.0.
Users are recommended to upgrade to version 1.2.2, which fixes the issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 34.4%
CVSS Severity
CVSS v3 Score 5.6
Products affected by CVE-2025-27867
-
cpe:2.3:a:apache:felix_http_webconsole_plugin:1.0.0
-
cpe:2.3:a:apache:felix_http_webconsole_plugin:1.1.0
-
cpe:2.3:a:apache:felix_http_webconsole_plugin:1.2.0