boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2025-23366MEDIUM
hal-console — Org.jboss.hal:hal-console: wildfly hal console cross-site scripting
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   R  C  L  L  N    4.8   .0045   37.6     —
AFFECTED
  Product                                                       Versions     Fixed
  hal-console                                                   unspecified  —
  Red Hat JBoss Enterprise Application Platform 7               unspecified  —
  Red Hat JBoss Data Grid 7                                     unspecified  —
  Red Hat JBoss Enterprise Application Platform 7               unspecified  —
  Red Hat JBoss Enterprise Application Platform 8               unspecified  —
  Red Hat JBoss Enterprise Application Platform Expansion Pack  unspecified  —
TIMELINE
  Jan 14  Reserved by redhat
  Jan 14  Published (CNA: redhat)
  Aug 7   RESCORED — CVE-2025-23366 (hal-console). CVSS 6.5 → 4.8 (NVD).
CWE-79 · CNA: redhat · CVSS v3.1 · 6 references · NVD status: Modified

Description

A flaw was found in the HAL Console in the Wildfly component, which does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a web page that is served to other users. The attacker must be authenticated as a user that belongs to management groups “SuperUser”, “Admin”, or “Maintainer”.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
January 14, 2025ReservedReserved by redhat
January 14, 2025PublishedPublished (CNA: redhat)
August 7, 2026RESCOREDRESCORED — CVE-2025-23366 (hal-console). CVSS 6.5 → 4.8 (NVD).

Affected

Affected products and packages — 6 rows
VendorProduct / PackageEcosystemVersion introducedFixed
hal-console
Red HatRed Hat JBoss Enterprise Application Platform 7
Red HatRed Hat JBoss Data Grid 7
Red HatRed Hat JBoss Enterprise Application Platform 7
Red HatRed Hat JBoss Enterprise Application Platform 8
Red HatRed Hat JBoss Enterprise Application Platform Expansion Pack

Weaknesses

CWE-79

References (6)

Related

Authoritative record: CVE-2025-23366 at cve.org

Vendors: red hat

Weaknesses: CWE-79

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-23366 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.