
CVE-2026-25006 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in 8theme XStore xstore allows Code Injection.This issue affects XStore: f… https://www.cve.org/CVERecord?id=CVE-2026-25006
Post summary
The entry announces a Basic XSS vulnerability (CVE‑2026‑25006) in 8theme XStore that allows code injection, with no PoC, exploit, or patch details provided.
