By vendor
Powerschool vulnerabilities
Known CVEs affecting Powerschool products, prioritized by severity, with SEC.co remediation and detection guidance.
1 published vulnerability
- CVE-2026-12425MEDIUM 6.1
PowerSchool Employee Access Center version 23.10 contains a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious JavaScript code into login URLs. When a user clicks a crafted link, the injected code executes in their browser with their privileges, potentially enabling session hijacking, credential theft, or unauthorized actions on their behalf.