Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 10 Nov 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:cmsimple-xh:cmsimple_xh:1.8.0:-:*:*:*:*:*:* |
Fri, 07 Nov 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cmsimple-xh
Cmsimple-xh cmsimple Xh |
|
| Vendors & Products |
Cmsimple-xh
Cmsimple-xh cmsimple Xh |
Thu, 06 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Thu, 06 Nov 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated reflected cross-site scripting vulnerability in the query handling of CMSimpleXH allows remote attackers to inject and execute arbitrary JavaScript in a victim's browser via a crafted request (e.g., a maliciously crafted POST login). Successful exploitation may lead to theft of session cookies, credential disclosure, or other client-side impacts. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-06T19:10:56.777Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-63588
Updated: 2025-11-06T19:10:16.922Z
Status : Analyzed
Published: 2025-11-06T17:15:46.197
Modified: 2025-11-10T17:29:28.327
Link: CVE-2025-63588
No data.
OpenCVE Enrichment
Updated: 2025-11-07T10:55:19Z