← All CVEs & advisories

ServiceNow CVE-2025-11450

ServiceNow Cross-Site Scripting

XSSCVSS 4.0 5.3Priority 11Disclosed 2025-10-10Verified

Risk & exploitation

PriorityLow · 11/100
EPSS0.001 · 17.8th pct
CISA KEVNo
Public exploitNone indexed

EPSS (FIRST) estimates a low likelihood of exploitation in the next 30 days (2026-06-10). Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.

Summary

ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could result in arbitrary code being executed within the browsers of ServiceNow users who click on a specially crafted link.

ServiceNow has addressed this vulnerability by deploying a relevant security update to the majority of hosted instances. Relevant security updates also have been provided to ServiceNow self-hosted customers, partners, and hosted customers with unique configurations. Further, the vulnerability is addressed in the listed patches and hot fixes. We recommend customers promptly apply appropriate updates or upgrade if they have not already done so.

Auto-generated stub from NVD. Detection signals and per-release fixed-in are pending manual authoring/verification; until a signal carries a verified match, the exposure check returns DORMANT/INVESTIGATE — never a false EXERCISED.

Affected releases & fixed-in

ReleaseFixed in
AustraliaGeneral Availability (GA)
ZurichPatch 1 Hot Fix 1a / Patch 2 / Patch 3
YokohamaPatch 7 Hot Fix 2a / Patch 8 / Patch 9
XanaduPatch 10 Hot Fix 1a / Patch 11
Washington DCPatch 10 Hot Fix 7b
Source & attribution

Per-release fixed-in VERIFIED against the ServiceNow-authored CVE Record (CNA shortName: SN) — affected[].versions[] boundaries, https://cveawg.mitre.org/api/cve/CVE-2025-11450 (retrieved 2026-06-08). The same patch matrix is in the login-gated ServiceNow KB; the public CVE Record is the citable source.

Regulatory mapping

Decision support, not a reporting determination.

Check your instance for CVE-2025-11450

References

Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.