CVE-2025-26158: Kashipara Online Attendance Management System

Medium severity, CVSS 5.6. EPSS: 0.3% chance of exploitation in the next 30 days.

A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the manage-employee.php page of Kashipara Online Attendance Management System V1.0. This vulnerability allows remote attackers to execute arbitrary scripts via the department parameter.

Affected products

  • Kashipara Online Attendance Management System: version 1.0 only

Published 2025-02-14. Last modified 2026-06-17.