VYPR
Medium severity5.4NVD Advisory· Published Oct 2, 2025· Updated Jun 17, 2026

CVE-2025-60782

CVE-2025-60782

Description

PHP Education Manager v1.0 is vulnerable to Cross Site Scripting (XSS) stored Cross-Site Scripting (XSS) vulnerability in the topics management module (topics.php). Attackers can inject malicious JavaScript payloads into the Titlefield during topic creation or updates.

Affected products

3

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.