Stored XSS Vulnerability in NotesCMS Affects Web Applications
CVE-2025-52036
What is CVE-2025-52036?
A vulnerability has been identified in NotesCMS that enables a stored XSS attack through the manipulation of service description titles. This issue arises in the page accessible via the '/index.php?route=categories' endpoint, allowing attackers to inject malicious scripts that are stored and executed in the context of the affected application. Confirmed in the source code as of May 8, 2024, and addressed in a fix issued on March 31, 2025, this vulnerability poses a risk of remote exploitation, emphasizing the importance of prompt updates to safeguard web applications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
