CVE-2025-63644

A stored cross-site scripting (XSS) vulnerability exists in pH7Software pH7-Social-Dating-CMS 17.9.1 in the user profile Description field.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ph7builder:ph7_social_dating_builder:17.9.1:-:*:*:*:*:*:*

History

23 Jan 2026, 14:44

Type Values Removed Values Added
CPE cpe:2.3:a:ph7builder:ph7_social_dating_builder:17.9.1:-:*:*:*:*:*:*
First Time Ph7builder
Ph7builder ph7 Social Dating Builder
References () https://drive.google.com/drive/folders/1mYDvUTnlTPCGTB-7tHD3pmu_wHtlMVRP - () https://drive.google.com/drive/folders/1mYDvUTnlTPCGTB-7tHD3pmu_wHtlMVRP - Exploit
References () https://medium.com/@rudranshsinghrajpurohit/cve-2025-63644-stored-cross-site-scripting-xss-vulnerability-in-ph7-social-dating-cms-23ed0e7eb853 - () https://medium.com/@rudranshsinghrajpurohit/cve-2025-63644-stored-cross-site-scripting-xss-vulnerability-in-ph7-social-dating-cms-23ed0e7eb853 - Third Party Advisory

22 Jan 2026, 04:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.1
v2 : unknown
v3 : 5.4

14 Jan 2026, 21:15

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

14 Jan 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-14 18:16

Updated : 2026-01-23 14:44


NVD link : CVE-2025-63644

Mitre link : CVE-2025-63644

CVE.ORG link : CVE-2025-63644


JSON object : View

Products Affected

ph7builder

  • ph7_social_dating_builder
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')