PatchSiren

xnx3 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW xnx3 CVE published 2026-01-05

CVE-2025-15452

A weakness has been identified in xnx3 wangmarket up to 4.9. This affects the function variableList of the file /admin/system/variableList.do of the component Backend Variable Search. Executing a manipulation of the argument Description can lead to cross site scripting. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was cont [truncated]

LOW xnx3 CVE published 2026-01-05

CVE-2025-15451

A security flaw has been discovered in xnx3 wangmarket up to 4.9, affecting the System Variables Page. Performing a manipulation of the argument Description results in cross site scripting. The attack may be initiated remotely. Defenders should assess exposure and prioritize verification and patching. The exploit has been released to the public and may be used for attacks. This vulnerability can lead to u [truncated]