216.73.216.133

CVE-2025-36746

· Published 12/12/2025 15:15 · Modified 16/12/2025 19:42

Labels: CVE-2025-36746 2025-12-12CVE-2025-36746[email protected]

Essential information

Published
12/12/2025 15:15
Modified
16/12/2025 19:42
Author
Creator
CVSS
4.8 MEDIUM (v3) 4.8 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

SolarEdge monitoring platform contains a Cross‑Site Scripting (XSS) flaw that allows an authenticated user to inject payloads into report names, which may execute in a victim’s browser during a deletion attempt.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
solaredge / solaredge monitoring platform cpe:2.3:a:solaredge:solaredge_monitoring_platform:-:*:*:*:*:saas:*:*

References