Back to Database
Status published
Medium
CVE-2025-6725
Cross-Site Scripting (XSS) in PdfViewer
Vulnerability Description
In the PdfViewer component, a Cross-Site Scripting (XSS) vulnerability is possible if a specially-crafted document has already been loaded and the user engages with a tool that requires the DOM to be re-rendered.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-6725
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.telerik.com/blazor-ui/documentation/knowledge-base/pdfviewer-xss-vulnerability-cve-2025-6725
- https://www.telerik.com/aspnet-core-ui/documentation/knowledge-base/kb-security-pdfviewer-xss-cve-2025-6725
- https://www.telerik.com/aspnet-mvc/documentation/knowledge-base/kb-security-pdfviewer-xss-cve-2025-6725
- https://www.telerik.com/kendo-jquery-ui/documentation/knowledge-base/kb-security-pdfviewer-xss-cve-2025-6725
- https://www.telerik.com/kendo-angular-ui/components/knowledge-base/kb-security-pdfviewer-xss-cve-2025-6725
- https://www.telerik.com/kendo-react-ui/components/knowledge-base/kb-security-pdfviewer-xss-cve-2025-6725
More from Progress Software
View All →CVE-2025-8868
Chef Automate compliance service SQL Injection Vulnerability
Critical
9.8
CVE-2025-6724
Chef Automate SQL Injection Vulnerability
High
8.8
CVE-2025-6723
Untrusted user data can lead to privilege escalation
Medium
5.8
CVE-2025-6505
Unauthorized access and impersonation can occur in versions 4.6.2.3226 and below of...
High
8.1
CVE-2025-6504
Possibilities of IP Spoofing via X-Forwarded-For (XFF) Header
High
8.4
Affected Vendor
Progress Software
View all reports →Affected Software
Kendo UI for jQuery, Kendo UI for Angular, KendoReact, Telerik UI for ASP.NET MVC, Telerik UI for ASP.NET Core, Telerik UI for Blazor
Vulnerable Versions:
2024.4.1112, 18.5.0, 5.10.0, 3.6.0
Timeline
Official Publish:
July 2nd, 2025
Last Modified:
July 2nd, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N