Vulnerability record · CVE-2025-27921 · published 5 May 2025
CVE-2025-27921: Srimax output messenger cross-site scripting vulnerability
Srimax · Output Messenger
A reflected cross-site scripting (XSS) vulnerability was discovered in Output Messenger before 2.0.63, where unsanitized input could be injected into the web application’s response. This vulnerability occurs when user-controlled input is reflected back into the browser without proper sanitization or encoding.
Description
A reflected cross-site scripting (XSS) vulnerability was discovered in Output Messenger before 2.0.63, where unsanitized input could be injected into the web application’s response. This vulnerability occurs when user-controlled input is reflected back into the browser without proper sanitization or encoding.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.outputmessenger.com/cve-2025-27921/ | Vendor Advisory |
| https://www.srimax.com/products-2/output-messenger/ | Product |
Track CVE-2025-27921 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-27921), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.