CVE-2025-60183
Plain English Summary
AI-powered analysis for quick understanding
This vulnerability allows an attacker to inject malicious scripts into the Silencesoft RSS Reader, which can then be stored and executed whenever users access the affected content. To exploit this, the attacker needs to have the ability to submit content that gets displayed to other users, making it a risk primarily in environments where untrusted users can post RSS feeds.
Technical Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in silence Silencesoft RSS Reader external-rss-reader allows Stored XSS.This issue affects Silencesoft RSS Reader: from n/a through <= 0.6.
Exploit Resources
Search for proof-of-concept code and exploit modules
Official References
Quick Information
Published
Feb 20, 2026
about 2 months ago
Last Modified
Feb 20, 2026
about 2 months ago