← Vulnerability feed

Vulnerability record · CVE-2025-67823 · published 15 January 2026

CVE-2025-67823: Mitel cx cross-site scripting vulnerability

Mitel · Cx

A vulnerability in the Multimedia Email component of Mitel MiContact Center Business through 10.2.0.10 and Mitel CX through 1.1.0.1 could allow an unauthenticated attacker to conduct a Cross-Site Scripting (XSS) attack due to insufficient input validation. A successful exploit requires user interaction where the email channel is enabled. This could allow an attacker to execute arbitrary scripts in the victim's browser or desktop client application.

8.2 CVSS 3.1 High EPSS 0.34% · top 75.4% CWE-79 · Cross-site scripting
8.2CVSS 3.1 base score
0.34%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the Multimedia Email component of Mitel MiContact Center Business through 10.2.0.10 and Mitel CX through 1.1.0.1 could allow an unauthenticated attacker to conduct a Cross-Site Scripting (XSS) attack due to insufficient input validation. A successful exploit requires user interaction where the email channel is enabled. This could allow an attacker to execute arbitrary scripts in the victim's browser or desktop client application.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-67823 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2021-3352Mitel micontact center business vulnerabilityThe Software Development Kit in Mitel MiContact Center Business from 8.0.0.0 through 8.1.4.1 and 9.0.0.0 through 9.3.1.0 could allow an unauthenticat…EPSS 1.0%8.1CVE-2024-42514Mitel micontact center business improper access control vulnerabilityA vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthenticated attacker to conduct a…EPSS 0.45%7.5CVE-2024-28069Mitel micontact center business vulnerabilityA vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a…EPSS 0.57%7.5CVE-2023-22854Mitel micontact center business vulnerabilityThe ccmweb component of Mitel MiContact Center Business server 9.2.2.0 through 9.4.1.0 could allow an unauthenticated attacker to download arbitrary …EPSS 0.60%7.1CVE-2020-24692Mitel micontact center business improper input validation vulnerabilityThe Ignite portal in Mitel MiContact Center Business before 9.3.0.0 could allow an attacker to execute arbitrary scripts due to insufficient input va…EPSS 0.42%6.8CVE-2024-28070Mitel micontact center business cross-site scripting vulnerabilityA vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a…EPSS 0.45%6.5CVE-2020-9379Mitel micontact center business vulnerabilityThe Software Development Kit of the MiContact Center Business with Site Based Security 8.0 through 9.0.1.0 before KB496276 allows an authenticated us…EPSS 0.92%6.1CVE-2024-35283Mitel micontact center business cross-site scripting vulnerabilityA vulnerability in the Ignite component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a stor…EPSS 0.26%

Source: NIST National Vulnerability Database (record CVE-2025-67823), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.