CVE-2025-63522: Medium severity FeehiCMS FeehiCMS vulnerability
Published Dec 1, 2025
·Updated
Reverse Tabnabbing vulnerability in FeehiCMS 2.1.1 in the Comments Management function
Affected Software
3 affected components
FeehiCMS FeehiCMS
Feehi Feehicms=2.1.1
composer/feehi/feehicms<=2.1.1
Event History
Dec 1, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·03:30 PM
Data Sourced
via GitHub·03:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-63522?
CVE-2025-63522 is classified as a high severity vulnerability due to the potential for exploitation through reverse tabnabbing.
2
How do I fix CVE-2025-63522?
To fix CVE-2025-63522, update FeehiCMS to version 2.1.2 or later, which includes a patch for the vulnerability.
3
What is reverse tabnabbing in the context of CVE-2025-63522?
In the context of CVE-2025-63522, reverse tabnabbing is a technique where a malicious website can change the location of a previously opened tab through a crafted link.
4
Which versions of FeehiCMS are affected by CVE-2025-63522?
FeehiCMS version 2.1.1 is the only affected version mentioned for CVE-2025-63522.
5
What measures can I take to protect against CVE-2025-63522 before applying the fix?
As an interim measure, mitigate CVE-2025-63522 by ensuring safe browsing practices and avoiding untrusted links in comments.