PatchSiren cyber security CVE debrief
CVE-2025-69140 SeventhQueen CVE debrief
CVE-2025-69140 is a high-severity Unauthenticated Cross Site Scripting (XSS) vulnerability in SweetDate Core versions before 1.1.5. With a CVSS score of 7.1, this vulnerability allows attackers to inject malicious scripts into web pages viewed by other users. The vulnerability was published on June 17, 2026, and immediately gained attention due to its high severity and potential for exploitation. Users of SweetDate Core should update to version 1.1.5 or later to mitigate this risk. This vulnerability highlights the importance of keeping software up-to-date and vigilant about potential security threats. Administrators should prioritize patching this vulnerability to prevent potential attacks.
- Vendor
- SeventhQueen
- Product
- SweetDate Core
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-17
- Original CVE updated
- 2026-06-17
- Advisory published
- 2026-06-17
- Advisory updated
- 2026-06-17
Who should care
Administrators and users of SweetDate Core versions before 1.1.5 should be aware of this vulnerability and take immediate action to update to a patched version. Additionally, security teams and IT professionals responsible for maintaining web applications should be aware of this vulnerability and monitor for potential exploitation attempts.
Technical summary
CVE-2025-69140 is a high-severity Unauthenticated Cross Site Scripting (XSS) vulnerability in SweetDate Core versions before 1.1.5. The vulnerability has a CVSS score of 7.1 and is classified as CWE-79. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L, indicating that the vulnerability can be exploited over the network with low attack complexity and no privileges required. The vulnerability allows attackers to inject malicious scripts into web pages viewed by other users.
Defensive priority
High
Recommended defensive actions
- Update SweetDate Core to version 1.1.5 or later
- Monitor for potential exploitation attempts
- Implement additional security measures such as input validation and output encoding
- Conduct regular security audits and vulnerability assessments
- Keep software and plugins up-to-date
- Use a web application firewall to detect and prevent attacks
Evidence notes
The vulnerability was reported by Patchstack and is classified as CWE-79. The CVSS score and vector were provided by the NVD. The vulnerability is considered high-severity due to its potential for exploitation and impact on affected systems.
Official resources
-
CVE-2025-69140 CVE record
CVE.org
-
CVE-2025-69140 NVD detail
NVD
-
Source item URL
nvd_modified
- Mitigation or vendor reference
public