Vulnerability Description
SolarEdge monitoring platform contains a Cross‑Site Scripting (XSS) flaw that allows an authenticated user to inject payloads into report names, which may execute in a victim’s browser during a deletion attempt.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Solaredge | Solaredge Monitoring Platform | - |
Related Weaknesses (CWE)
References
- https://csirt.divd.nl/CVE-2025-36746Third Party Advisory
- https://csirt.divd.nl/DIVD-2025-00022/Broken Link
FAQ
What is CVE-2025-36746?
CVE-2025-36746 is a vulnerability with a CVSS score of 5.4 (MEDIUM). SolarEdge monitoring platform contains a Cross‑Site Scripting (XSS) flaw that allows an authenticated user to inject payloads into report names, which may execute in a victim’s browser during a deleti...
How severe is CVE-2025-36746?
CVE-2025-36746 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-36746?
Check the references section above for vendor advisories and patch information. Affected products include: Solaredge Solaredge Monitoring Platform.