Vulnerabilities (CVE)

Filtered by vendor Oranbyte Subscribe
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-51967 1 Oranbyte 1 School Management System 2025-09-09 N/A 6.1 MEDIUM
A Reflected Cross-site Scripting (XSS) vulnerability exists in the themeSet.php file of ProjectsAndPrograms School Management System 1.0. The application fails to sanitize user-supplied input in the theme POST parameter, allowing an attacker to inject and execute arbitrary JavaScript in a victim's browser.