CVE-2025-63520: XSS
Published Dec 1, 2025
·Updated
Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 via the id parameter of the User Update function (?r=user%2Fupdate).
Affected Software
3 affected components
FeehiCMS FeehiCMS
Feehi Feehicms=2.1.1
composer/feehi/feehicms=2.1.1
Event History
Dec 1, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·03:30 PM
Data Sourced
via GitHub·03:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-63520?
CVE-2025-63520 is classified as a Cross Site Scripting (XSS) vulnerability that can pose significant security risks.
2
How do I fix CVE-2025-63520?
To fix CVE-2025-63520, ensure proper input validation and sanitization for the 'id' parameter in the User Update function.
3
What versions of FeehiCMS are affected by CVE-2025-63520?
FeehiCMS version 2.1.1 is affected by CVE-2025-63520.
4
Can CVE-2025-63520 lead to data theft?
Yes, CVE-2025-63520 can potentially allow attackers to execute malicious scripts in the context of the user's browser, leading to data theft.
5
Is there a workaround for CVE-2025-63520?
A temporary workaround for CVE-2025-63520 is to disable the User Update function until a patch is applied.