Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
6.5
Advanced iFrame: Unfiltered User Input Can Execute Malicious Code
CVE-2026-25453
Summary
Advanced iFrame's web page generation doesn't properly filter user input, which can allow attackers to inject malicious code into web pages. This can lead to unauthorized access to sensitive data or actions. To protect your website, update to a fixed version of Advanced iFrame, or replace it with a secure alternative.
Original title
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mdempfle Advanced iFrame advanced-iframe allows DOM-Based XSS.This issue affects Advanced iFram...
Original description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mdempfle Advanced iFrame advanced-iframe allows DOM-Based XSS.This issue affects Advanced iFrame: from n/a through <= 2025.10.
nvd CVSS3.1
6.5
Vulnerability type
CWE-79
Cross-site Scripting (XSS)
Published: 19 Feb 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026