Known CVE
Label Studio < 1.18.0 - Reflected XSS
Label Studio < 1.18.0 contains a stored XSS caused by improper sanitization in POST /projects/upload-example/ endpoint, letting attackers inject malicious scripts to hijack sessions and perform unauthorized actions, exploit requires sending crafted requests.
CVE-2025-47783
Medium2025CVSS 6.1CWE-79
label-studio · xss · reflected
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website