Critical
Low
Medium

CVE-2025-57292

Overview

Todoist v8484 contains a stored cross-site scripting (XSS) vulnerability in the avatar upload functionality. The application fails to properly validate the MIME type and sanitize image metadata.

Critical
Low
Medium
No items found.

Package:

Impact:

Fix:

Year:

CVSS:

Severity:

Affected Components

Location

Stop the waste.
Protect your environment with Kodem.

Get a personalized demo
Get a personalized demo