Description
Cross Site Scripting (XSS) vulnerability in Fiora chat application 1.0.0 allows arbitrary JavaScript execution when malicious SVG files are rendered by other users.
Recommendation
No fix is available yet. Followings are affected versions:
- = 1.0.0
References
Could your website be exposed too?
SmartScanner can check your website for Fiora chat user avatar is vulnerable to XSS via SVG files and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Fiora chat group avatar is vulnerable to XSS via SVG files - CVE-2025-56515
- Lobe Chat Desktop vulnerable to Remote Code Execution via XSS in Chat Messages - CVE-2025-59417
- Bootstrap Multiselect Vulnerable to CSRF and Reflective XSS via Arbitrary POST Data - CVE-2025-47204
- Quill is vulnerable to XSS via HTML export feature - CVE-2025-15056
You might also like:
See something that needs correcting? Let us knowUpdated October 13, 2025


