This page aggregates publicly disclosed CVE and security risk information related to visicut, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2025-43708 | VisiCut 2.1 allows stack consumption via an XML document with nested set elements, as demonstrated by a java.util.HashMap StackOverflowError when reference='../../../set/set[2]' is used, aka an "insecure deserialization" issue. | [email protected] | 3.3 | 0.43% | 2025-04-17 | 2025-09-24 |
| CVE-2025-25940 | VisiCut 2.1 allows code execution via Insecure XML Deserialization in the loadPlfFile method of VisicutModel.java. | [email protected] | 9.8 | 1.64% | 2025-03-10 | 2025-06-23 |