Stored XSS Vulnerability in NotesCMS Affects Web Applications
CVE-2025-52036

6.1MEDIUM

Key Information:

Vendor

NotesCMS

Status
Vendor
CVE Published:
26 August 2025

What is CVE-2025-52036?

A vulnerability has been identified in NotesCMS that enables a stored XSS attack through the manipulation of service description titles. This issue arises in the page accessible via the '/index.php?route=categories' endpoint, allowing attackers to inject malicious scripts that are stored and executed in the context of the affected application. Confirmed in the source code as of May 8, 2024, and addressed in a fix issued on March 31, 2025, this vulnerability poses a risk of remote exploitation, emphasizing the importance of prompt updates to safeguard web applications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.