CVE-2026-25496 is a low severity vulnerability with a CVSS score of 0.0. No known exploits currently, and patches are available.
Very low probability of exploitation
EPSS predicts the probability of exploitation in the next 30 days based on real-world threat data, complementing CVSS severity scores with actual risk assessment.
A stored XSS vulnerability exists in the Number field type settings. The Prefix and Suffix fields are rendered using the |md|raw Twig filter without proper escaping, allowing script execution when the Number field is displayed on users' profiles.
allowAdminChanges is enabled in production, which is against our security recommendations.<img src=x onerror="alert('Number Prefix/Suffix XSS')" hidden>
/admin/myaccount) or any user profile (/admin/users/{id})Sanitize prefix/suffix before rendering or use |e filter instead of |raw.
Please cite this page when referencing data from Strobes VI. Proper attribution helps support our vulnerability intelligence research.