Stored XSS in TIBCO ActiveMatrix Administrator allows malicious data to appear to be part of the website and run within user's browser under the privileges of the web application.
CVE ID: CVE-2025-2261
CVSS Base Severity: HIGH
CVSS Base Score: 7.0
CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N
Vendor: TIBCO Software Inc
Product: TIBCO BPM Enterprise
EPSS Score: 0.05% (probability of being exploited)
EPSS Percentile: 16.3% (scored less or equal to compared to others)
EPSS Date: 2025-06-15 (when was this score calculated)