CVE-2025-60646: XSS
Published Nov 12, 2025
·Updated
A stored cross-site scripting (XSS) in the Business Line Management module of Xxl-api v1.3.0 attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter.
Affected Software
2 affected components
xxl-api xxl-api
Xuxueli Xxl-api<=1.3.0
Event History
Nov 12, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-60646?
CVE-2025-60646 is a high-severity vulnerability due to its potential for stored cross-site scripting attacks.
2
How do I fix CVE-2025-60646?
To fix CVE-2025-60646, eliminate unsanitized input in the Name parameter and implement proper input validation and output encoding.
3
What software versions are affected by CVE-2025-60646?
CVE-2025-60646 affects Xxl-api v1.3.0.
4
What type of vulnerability is CVE-2025-60646?
CVE-2025-60646 is a stored cross-site scripting (XSS) vulnerability.
5
What can attackers do by exploiting CVE-2025-60646?
Attackers can execute arbitrary web scripts or HTML by injecting a crafted payload into the Name parameter.