CVE-2025-51857 – Halo XSS Vulnerability in AttachmentReconciler Class

The following table lists the changes that have been made to the
CVE-2025-51857 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Aug. 05, 2025

    Action Type Old Value New Value
    Added Description The reconcile method in the AttachmentReconciler class of the Halo system v.2.20.18LTS and before is vulnerable to XSS attacks.
    Added Reference http://halo.com
    Added Reference https://gist.github.com/this1slwl/d714514635119159607c14faebbbcf20
    Added Reference https://github.com/halo-dev/halo
Share the Post:

Related Posts