The following table lists the changes that have been made to the
CVE-2025-53839 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.
-
New CVE Received
by [email protected]Jul. 15, 2025
Action Type Old Value New Value Added Description DRACOON is a file sharing service, and the DRACOON Branding Service allows customers to customize their DRACOON interface with their brand. Versions of the DRACOON Branding Service prior to 2.10.0 are vulnerable to cross-site scripting. Improper neutralization of input from administrative users could inject HTML code into the workflow for newly onboarded users. A fix was made available in version 2.10.0 and rolled out to the DRACOON service. DRACOON customers do not need to take action. Added CVSS V3.1 AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N Added CWE CWE-79 Added Reference https://github.com/dracoon/security-advisories/security/advisories/GHSA-jv2h-8mw7-mc97