Loading
A reflected cross-site scripting (XSS) vulnerability was discovered in Output Messenger before 2.0.63, where unsanitized input could be injected into the web application’s response. This vulnerability occurs when user-controlled input is reflected back into the browser without proper sanitization or encoding.
Use CWE-79, Srimax vendor hub and Output Messenger product page to widen CVE-2025-27921 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-27920 for nearby disclosures in the same product family.