CVE-2025-5015 – AccuWeather Custom RSS Widget Cross-Site Scripting Vulnerability

CVE ID : CVE-2025-5015

Published : June 25, 2025, 5:15 p.m. | 16 hours, 25 minutes ago

Description : A cross-site scripting vulnerability exists in the AccuWeather and Custom RSS widget that allows an unauthenticated user to replace the RSS feed URL with a malicious one.

Severity: 8.8 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

Go to Source