CVE-2025-55287 Details
Description
Genealogy is a family tree PHP application. Prior to 4.4.0, Authenticated Stored Cross-Site Scripting (XSS) vulnerability was identified in the Genealogy application. Authenticated attackers could run arbitrary JavaScript in another user’s session, leading to session hijacking, data theft, and UI manipulation. This vulnerability is fixed in 4.4.0.
A stored cross-site scripting vulnerability has been identified in the Genealogy PHP application, affecting all versions prior to 4.4.0. This vulnerability allows authenticated attackers to inject arbitrary JavaScript that is executed in the context of another user's session. The impact of this vulnerability includes session hijacking, data theft, and manipulation of the user interface.
Users are advised to upgrade to version 4.4.0 or later, where this vulnerability has been fixed. For those unable to upgrade immediately, it is recommended to sanitize or escape user-generated content before displaying it, and to review file storage settings to prevent unauthorized access to sensitive files.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/MGeurts/genealogy/commit/1683b3cbea5e52c99291fa231b7bc8c33f33c33f | [email protected] | Patch |
| https://github.com/MGeurts/genealogy/security/advisories/GHSA-j457-9m86-6q5r | [email protected] | MitigationThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| kreaweb genealogy | < 4.4.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 3, 2025 | Initial Analysis | [email protected] |
| Aug 18, 2025 | New CVE Received | [email protected] |