CVE-2025-13672Disclosure(opentext / web_site_management_server)

LOWCVSS 5.4 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch opentext web_site_management_server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Web Site Management Server allows Reflected XSS. The vulnerability could allow injecting malicious JavaScript inside URL parameters that was then rendered with the preview of the page, so that malicious scripts could be executed on the client side. This issue affects Web Site Management Server: 16.7.0, 16.7.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • web_site_management_server

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
web_site_management_server

2 versions affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-20: 2Patch / Workaround · 2026-02-20: 1Technical Details · 2026-02-20: 202-20
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • CyberMI@m1_cyber
    Patch

    🚨 CVE-2025-13672 ثغرة Reflected XSS تضرب OpenText WSM 16.7.0–16.7.1 بخطورة 7/10. يمكن استغلالها عبر حقن JavaScript في الرابط لتنفيذه داخل متصفح الضحية (سرقة جلسات / تنفيذ أوامر باسم المستخدم). التحديث فورًا للإصدار الآمن ضروري. #CyberSecurity #XSS #CVE #CYBER_MI https://t.co/gnmiE2dBXK

    Post summary

    The tweet announces a moderate‑severity XSS vulnerability in OpenText WSM 16.7.x and urges users to apply the available patch immediately.

    1002044
    2 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-13672 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Web Site Management Server allows Reflected XSS… https://www.cve.org/CVERecord?id=CVE-2025-13672

    Post summary

    The text announces CVE-2025-13672, detailing a reflected XSS vulnerability in OpenText Web Site Management Server, but does not provide a PoC, exploit, patch, or active exploitation evidence.

    00000100
    56.4K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appopentextweb_site_management_server16.7.0--
Appopentextweb_site_management_server16.7.1--

Explore more