
CVE-2025-28121 – Online Exam Mastering System 1.0 Cross Site Scripting
https://notcve.org/view.php?id=CVE-2025-28121
21 Apr 2025 — code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in feedback.php via the "q" parameter allowing remote attackers to execute arbitrary code. • https://code-projects.org/online-exam-mastering-system-php • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2025-29287
https://notcve.org/view.php?id=CVE-2025-29287
21 Apr 2025 — An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file. • http://cms.com • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVE-2025-29659
https://notcve.org/view.php?id=CVE-2025-29659
21 Apr 2025 — Yi IOT XY-3820 6.0.24.10 is vulnerable to Remote Command Execution via the "cmd_listen" function located in the "cmd" binary. • https://github.com/Yasha-ops/RCE-YiIOT • CWE-285: Improper Authorization •

CVE-2025-29660
https://notcve.org/view.php?id=CVE-2025-29660
21 Apr 2025 — This service lacks proper input validation, allowing attackers to execute arbitrary scripts present on the device by sending specially crafted TCP requests using directory traversal techniques. • https://github.com/Yasha-ops/RCE-YiIOT • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2025-3472 – Ocean Extra <= 2.4.6 - Unauthenticated Arbitrary Shortcode Execution
https://notcve.org/view.php?id=CVE-2025-3472
21 Apr 2025 — The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.6. ... This makes it possible for unauthenticated attackers to execute arbitrary shortcodes when WooCommerce is also installed and activated. • https://www.wordfence.com/threat-intel/vulnerabilities/id/74428e76-1946-408f-8adc-24ab4b7e46c5?source=cve • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2025-3826 – SourceCodester Web-based Pharmacy Product Management System add-supplier.php cross site scripting
https://notcve.org/view.php?id=CVE-2025-3826
20 Apr 2025 — A vulnerability, which was classified as problematic, was found in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unknown part of the file add-supplier.php. The manipulation of the argument txtsupplier_name/txtaddress leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. • https://vuldb.com/?id.305733 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2025-3825 – SourceCodester Web-based Pharmacy Product Management System add-category.php cross site scripting
https://notcve.org/view.php?id=CVE-2025-3825
20 Apr 2025 — A vulnerability, which was classified as problematic, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected by this issue is some unknown functionality of the file add-category.php. The manipulation of the argument txtcategory_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. • https://vuldb.com/?id.305732 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2025-3824 – SourceCodester Web-based Pharmacy Product Management System add-product.php cross site scripting
https://notcve.org/view.php?id=CVE-2025-3824
20 Apr 2025 — A vulnerability classified as problematic was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected by this vulnerability is an unknown functionality of the file add-product.php. The manipulation of the argument txtprice/txtproduct_name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. • https://vuldb.com/?id.305731 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2025-3823 – SourceCodester Web-based Pharmacy Product Management System add-stock.php cross site scripting
https://notcve.org/view.php?id=CVE-2025-3823
20 Apr 2025 — A vulnerability classified as problematic has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected is an unknown function of the file add-stock.php. The manipulation of the argument txttotalcost/txtproductID/txtprice/txtexpirydate leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. • https://vuldb.com/?id.305730 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2025-3822 – SourceCodester Web-based Pharmacy Product Management System changepassword.php cross site scripting
https://notcve.org/view.php?id=CVE-2025-3822
20 Apr 2025 — A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file changepassword.php. The manipulation of the argument txtconfirm_password/txtnew_password/txtold_password leads to cross site scripting. The attack may be initiated remotely. • https://vuldb.com/?id.305729 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-94: Improper Control of Generation of Code ('Code Injection') •