VYPR
Moderate severityNVD Advisory· Published Jan 14, 2026· Updated Jan 22, 2026

CVE-2025-63644

CVE-2025-63644

Description

A stored cross-site scripting (XSS) vulnerability exists in pH7Software pH7-Social-Dating-CMS 17.9.1 in the user profile Description field.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
ph7software/ph7builderPackagist
<= 17.9.1

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.