CVE-2025-54057

Published Nov 27, 2025

Last updated 3 months ago

Overview

Description
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache SkyWalking. This issue affects Apache SkyWalking: <= 10.2.0. Users are recommended to upgrade to version 10.3.0, which fixes the issue.
Source
security@apache.org
NVD status
Analyzed
Products
skywalking

Risk scores

CVSS 3.1

Type
Secondary
Base score
6.1
Impact score
2.7
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Severity
MEDIUM

Weaknesses

security@apache.org
CWE-80

Social media

Hype score
Not currently trending
  1. #VulnerabilityReport #ApacheSkyWalking Security Alert: Apache SkyWalking Stored XSS Vulnerability (CVE-2025-54057) https://t.co/g9QcCVZfaM

    @Komodosec

    3 Jan 2026

    76 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Security Alert: Apache SkyWalking Stored XSS Vulnerability (CVE-2025-54057) https://t.co/QdOhf9PxPd

    @CrowdCyber_Com

    30 Nov 2025

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. ⚠️⚠️ CVE-2025-54057: Apache SkyWalking Stored XSS Vulnerability 🔗FOFA Link: https://t.co/EXwSf85yd5 🎯2.6k+ Results are found on the https://t.co/pb16tGYaKe nearly year. FOFA Query: app="APACHE-Skywalking" 🔖Refer: https://t.co/VBKO3N1q5g #OSINT #FOFA #CyberSecurit

    @fofabot

    27 Nov 2025

    2098 Impressions

    3 Retweets

    35 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2025-54057 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache SkyWalking. This issue affects Apache SkyWalking: &lt;= 10.2.0. U… https://t.co/75AIZP9HYg

    @CVEnew

    27 Nov 2025

    310 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. ⚠️ CVE-2025-54057 🖥️ Apache SkyWalking stored XSS vulnerability 💬 allows attackers to inject malicious JavaScript into SkyWalking UI fields, leading to persistent XSS, session hijacking, and unauthorized actions when admins view compromised pages. 🔗 https://t.co/p

    @ransomnews

    27 Nov 2025

    195 Impressions

    1 Retweet

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2025-54057 CVE-2025-54057 https://t.co/EQHl3NoLNg

    @VulmonFeeds

    27 Nov 2025

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations