CVE-2026-12425
Last modified
CVE-2026-12425 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PowerSchool Employee Access Center allows Cross-Site Scripting (XSS). This issue affects Employee Access Center: 23.10. It is possible to add in javascript code after the login URL and have it be eval()'d in the page and execute in the context of the user.. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PowerSchool Employee Access Center allows Cross-Site Scripting (XSS). This issue affects Employee Access Center: 23.10. It is possible to add in javascript code after the login URL and have it be eval()'d in the page and execute in the context of the user.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Powerschool | Employee Access Center | 23.10 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-12425?
How severe is CVE-2026-12425?
How do I fix CVE-2026-12425?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-12415The Invoice Generator plugin for WordPress is vulnerable to …9.8
- CVE-2026-12416The Invoice Generator plugin for WordPress is vulnerable to …9.8
- CVE-2026-12417The SignUp & SignIn plugin for WordPress is vulnerable to Au…9.8
- CVE-2026-12418The User Frontend: AI Powered Frontend Posting, User Directo…5.3
- CVE-2026-1242The BlockSpare plugin for WordPress is vulnerable to authori…4.3
- CVE-2026-12421The ARforms plugin for WordPress is vulnerable to Stored Cro…7.2
- CVE-2026-12426The Members – Membership & User Role Editor Plugin plugin fo…5.3
- CVE-2026-12428The Blocks for ACF Fields plugin for WordPress is vulnerable…6.5
- CVE-2026-1243IBM Content Navigator 3.0.15, 3.1.0, and 3.2.0 is vulnerable…5.4
- CVE-2026-12430The Blocksy Companion plugin for WordPress is vulnerable to …4.4
- CVE-2026-12432The WP Full Stripe Free plugin for WordPress is vulnerable t…5.3
- CVE-2026-12433The Hydra Booking – Appointment Scheduling & Booking Calenda…4.3
Are you affected by CVE-2026-12425?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
