CVE-2025-29018: Codeastro Internet Banking System

Medium severity, CVSS 4.8. EPSS: 0.3% chance of exploitation in the next 30 days.

A Stored Cross-Site Scripting (XSS) vulnerability exists in the name parameter of pages_add_acc_type.php in Code Astro Internet Banking System 2.0.0.

Affected products

  • Codeastro Internet Banking System: version 2.0.0 only

Published 2025-04-09. Last modified 2026-06-17.