Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/dotadrien/cve-2025-60656
Vulnerability AnalysisWeb Application ExploitationWeb SecurityPapers & ResearchLearning & Education
GitHubdotadrien/cve-2025-60656

CVE-2025-60656

Stored XSS vulnerability proof-of-concept for Script Pag's 'Recent Ads' module, exploiting unsanitized double quotes in image URL fields to execute arbitrary JavaScript on the homepage.

View Repository
48 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-60656 - Stored Cross-Site Scripting (XSS) on Homepage

ResearchersDotAdrien
Severity8.5 (HIGH) (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N)
SoftwareScript Pag

Description

A stored Cross-Site Scripting (XSS) vulnerability exists on the homepage via the "Recent Ads" module. The image URL field fails to sanitize double quotes ("). An attacker can inject a payload such as https://google.com/image.png", which triggers when any user visits the homepage.

Download Tool