PatchSiren

Phraseanet CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Phraseanet CVE published 2026-02-11

CVE-2018-25157

CVE-2018-25157 is a stored cross-site scripting vulnerability in Phraseanet 4.0.3 that allows authenticated users to inject malicious scripts through crafted file names during document uploads. This vulnerability can lead to potential cookie theft or user redirection when the file is viewed. Defenders responsible for Phraseanet installations should assess exposure and prioritize remediation to prevent pot [truncated]