CVE-2025-41065Disclosure

LOWCVSS 5.1 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Stored Cross-Site Scripting (XSS) vulnerability type in LUNA software v7.5.5.6. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by inyecting a malicious payload through the 'Edit Batch Name' function. THe payload is stored by the application and subsequently displayed without proper sanitization when other users access it. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-02-03)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-02: 1Mentions · 2026-02-03: 2Technical Details · 2026-02-02: 1Technical Details · 2026-02-03: 202-0202-03
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-021
Disclosure1
2026-02-032
Disclosure2
Full discourse3 posts
  • INCIBE-CERT@incibe_cert
    Disclosure

    ⚠️#INCIBEaviso | Cross-Site Scripting (XSS) almacenado en LUNA de #LunaImaging #CVE #CVE-2025-41065 https://www.incibe.es/incibe-cert/alerta-temprana/avisos/cross-site-scripting-xss-almacenado-en-luna-de-luna-imaging #AvisosDeSeguridad #TI #CNA #0day https://t.co/LJ1ajgro8F

    Post summary

    Incibe issued a security alert disclosing a stored XSS flaw (CVE‑2025‑41065) in Luna Imaging software.

    11050630
    42.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-41065 Stored Cross-Site Scripting (XSS) vulnerability type in LUNA software v7.5.5.6. This vulnerability allows an attacker to execute JavaScript code in the victim's brows… https://www.cve.org/CVERecord?id=CVE-2025-41065

    Post summary

    The text announces a stored XSS flaw (CVE‑2025‑41065) in LUNA v7.5.5.6, noting its potential to run JavaScript in a victim’s browser, but does not provide any proof of concept, exploit code, or mitigation details.

    00010234
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-41065 Stored Cross-Site Scripting in LUNA Software v7.5.5.6 via Batch Name Function https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-41065

    Post summary

    A stored XSS vulnerability (CVE-2025-41065) has been disclosed for LUNA Software v7.5.5.6, affecting the Batch Name function.

    0000056
    4.0K followersView on X

Explore more