vciy

Juniper Networks Junos Space: 24 records in one advisory

24 records announced together, published 2025-10-09, every one of them citing the same advisory.

The advisory

Every record in this batch cites https://supportportal.juniper.net/JSA103140. That is the CNA's own reference, held in the index, and it is why these records are on one page.

What the records offer

All 24 records publish a fixed version.

No record in this batch is listed by CISA in held sources.

17 of 24 records name something of its own. For the other 7, held sources say the same thing about each.

Most commonly mapped weakness across the batch: CWE-79 Improper Neutralization of Input During…

What this page does not cover

Every record citing this advisory is on this page.

The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.

Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.

CVE-2025-59978Junos Space: Stored cross-site scripting vulnerability in web applicationCWE-79 Improper Neutralization of Input During…
CVE-2025-59981Junos Space: Device Template Definition page is vulnerable to reflected cross-site script injectionCWE-79 Improper Neutralization of Input During…
CVE-2025-59982Junos Space: Dashboard Search field is vulnerable to reflected cross-site script injectionCWE-79 Improper Neutralization of Input During…
CVE-2025-59983Junos Space: Template Definition page is vulnerable to reflected cross-site script injectionCWE-79 Improper Neutralization of Input During…
CVE-2025-59984Junos Space: Global Search is vulnerable to reflected cross-site script injectionCWE-79 Improper Neutralization of Input During…
CVE-2025-59985Junos Space: Purging Policy field is vulnerable to reflected cross-site script injectionCWE-79 Improper Neutralization of Input During…
CVE-2025-59986Junos Space: Input fields in Model Devices are vulnerable to reflected cross-site script injectionCWE-79 Improper Neutralization of Input During…
CVE-2025-59987Junos Space: The arbitrary device search field is vulnerable to reflected cross-site script injectionCWE-79 Improper Neutralization of Input During…
CVE-2025-59988Junos Space: Generate Report page is vulnerable to reflected cross-site script injectionCWE-79 Improper Neutralization of Input During…
CVE-2025-59989Junos Space: Device Discovery page is vulnerable to reflected cross-site script injectionCWE-79 Improper Neutralization of Input During…
CVE-2025-59990Junos Space: Template creation pages are vulnerable to reflected cross-site script injectionCWE-79 Improper Neutralization of Input During…
CVE-2025-59991Junos Space: Device Management pages are vulnerable to reflected cross-site script injectionCWE-79 Improper Neutralization of Input During…
CVE-2025-59992Junos Space: Secure Console page is vulnerable to reflected cross-site script injectionCWE-79 Improper Neutralization of Input During…
CVE-2025-59993Junos Space: Space Node Setting fields are vulnerable to reflected cross-site script injectionCWE-79 Improper Neutralization of Input During…
CVE-2025-59994Junos Space: Quick Template page is vulnerable to reflected cross-site script injectionCWE-79 Improper Neutralization of Input During…
CVE-2025-59995Junos Space: Template creation through Definition is vulnerable to reflected cross-site script injectionCWE-79 Improper Neutralization of Input During…
CVE-2025-59996Junos Space: Configuration View page is vulnerable to reflected cross-site script injectionCWE-79 Improper Neutralization of Input During…
CVE-2025-59997Junos Space: Fields in the CLI Configlets are vulnerable to reflected cross-site script injectionCWE-79 Improper Neutralization of Input During…
CVE-2025-59998Junos Space: Archive Logs screen is vulnerable to reflected cross-site script injectionCWE-79 Improper Neutralization of Input During…
CVE-2025-59999Junos Space: API Access Profiles page is vulnerable to reflected cross-site script injectionCWE-79 Improper Neutralization of Input During…
CVE-2025-60000Junos Space: Generate Report page is vulnerable to reflected cross-site script injectionCWE-79 Improper Neutralization of Input During…
CVE-2025-60001Junos Space: Create Quick Template page is vulnerable to reflected cross-site script injectionCWE-79 Improper Neutralization of Input During…
CVE-2025-60002Junos Space: Template Definitions page is vulnerable to reflected cross-site script injectionCWE-79 Improper Neutralization of Input During…
CVE-2025-60009Junos Space: CLI Configlet page is vulnerable to reflected cross-site script injectionCWE-79 Improper Neutralization of Input During…

24 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.