Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 13 Feb 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ph7builder
Ph7builder ph7 Social Dating Builder |
|
| CPEs | cpe:2.3:a:ph7builder:ph7_social_dating_builder:17.9.1:-:*:*:*:*:*:* | |
| Vendors & Products |
Ph7builder
Ph7builder ph7 Social Dating Builder |
Sat, 15 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ph7software
Ph7software ph7-social-dating-cms |
|
| Vendors & Products |
Ph7software
Ph7software ph7-social-dating-cms |
Thu, 13 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Wed, 12 Nov 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored cross-site scripting (XSS) vulnerability exists in pH7Software pH7-Social-Dating-CMS 17.9.1 in the application's message system. Unsanitized message content submitted by one user is persisted by the server and later rendered in another user's Inbox view without appropriate context-aware encoding. As a result, attacker-controlled content executes in the recipient's browser context when the Inbox message is viewed. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-13T15:48:25.326Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-63645
Updated: 2025-11-13T15:48:20.428Z
Status : Analyzed
Published: 2025-11-12T22:15:49.387
Modified: 2026-06-17T09:53:18.757
Link: CVE-2025-63645
No data.
OpenCVE Enrichment
Updated: 2025-11-15T22:07:52Z