CVE detail
CVE-2021-25790 — CVE-2021-25790
Published 2021-07-23 · Modified 2026-06-17 · Vendor house_rental_and_property_listing_php_project · Product house_rental_and_property_listing_php · Source nvd
MEDIUM
severity
CVSS-derived band
0.0088
EPSS probability
exploitation probability, 30d
56.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Multiple stored cross site scripting (XSS) vulnerabilities in the "Register" module of House Rental and Property Listing 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in all text fields except for Phone Number and Alternate Phone Number.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References