---
id: CVE-2025-13784
title: >-
  A weakness has been identified in yungifez Skuul School Management System up
  to 2.6.5
summary: >-
  A weakness has been identified in yungifez Skuul School Management System up
  to 2.6.5. This vulnerability affects unknown code of the file
  /dashboard/schools/1/edit of the component SVG File Handler. This manipulation
  causes cross site s…
severity: low
cvss: 2.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
  - CWE-94
  - CWE-79
vendor: yungifez
product: skuul
affected:
  - skuul <= 2.6.5
published: '2025-11-30'
updated: '2026-09-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13784'
references:
  - url: 'https://gist.github.com/thezeekhan/7fc54fd44bc5f318be0350b367b2d8ff'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.333788'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.333788'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.689012'
    label: cna@vuldb.com
  - url: 'https://gist.github.com/thezeekhan/7fc54fd44bc5f318be0350b367b2d8ff'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: 'https://vuldb.com/?submit.689012'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.0028
epssPercentile: 0.20801
ingestedAt: '2026-09-03T03:55:22.310Z'
---

## Overview

A weakness has been identified in yungifez Skuul School Management System up to 2.6.5. This vulnerability affects unknown code of the file /dashboard/schools/1/edit of the component SVG File Handler. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `skuul <= 2.6.5`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
