CVE-2025-63644: XSS
Published Jan 14, 2026
·Updated
A stored cross-site scripting (XSS) vulnerability exists in pH7Software pH7-Social-Dating-CMS 17.9.1 in the user profile Description field.
Affected Software
2 affected components
pH7Software pH7-Social-Dating-CMS
Ph7builder Ph7 Social Dating Builder=17.9.1
Event History
Jan 14, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-63644?
CVE-2025-63644 is classified as a medium severity stored cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2025-63644?
To fix CVE-2025-63644, sanitize user input in the Description field of user profiles to prevent script injection.
3
What software is affected by CVE-2025-63644?
The vulnerability CVE-2025-63644 affects pH7Software pH7-Social-Dating-CMS version 17.9.1.
4
Can CVE-2025-63644 lead to data theft?
Yes, CVE-2025-63644 may allow attackers to steal sensitive user information through malicious scripts.
5
Is CVE-2025-63644 exploitable remotely?
Yes, CVE-2025-63644 can be exploited remotely by attacking the website's user profile edit functionality.