PT-2025-46721 · Ph7Software · Ph7-Social-Dating-Cms

Published

2025-11-12

·

Updated

2026-02-13

·

CVE-2025-63645

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions pH7Software pH7-Social-Dating-CMS version 17.9.1
Description A stored cross-site scripting (XSS) issue exists in the application's message system. Unsanitized message content submitted by a user is stored by the server and displayed to other users without proper encoding. This allows attacker-controlled content to execute in the recipient’s browser when viewing messages in their Inbox. The message content submitted by a user is not properly sanitized before being stored and rendered.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-63645

Affected Products

Ph7-Social-Dating-Cms