Stored XSS Vulnerability in NotesCMS Affecting Remote Services
CVE-2025-52035

6.1MEDIUM

Key Information:

Vendor

NotesCMS

Status
Vendor
CVE Published:
26 August 2025

What is CVE-2025-52035?

A stored XSS vulnerability exists in NotesCMS, specifically affecting the /index.php?route=notes page. This security flaw allows an attacker to manipulate the content of service titles, potentially leading to malicious script execution when the affected page is loaded by users. The vulnerability was identified in the source code as of May 8, 2024, and poses a risk as it can be exploited remotely. The issue was subsequently addressed in a later commit on March 31, 2025, providing a crucial update for users to secure their applications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.