MEDIUM6.1
GHSA-657c-wxg6-jmqv
pH7-Social-Dating-CMS affected by a stored cross-site scripting (XSS) vulnerability
Details
A stored cross-site scripting (XSS) vulnerability exists in pH7Software pH7-Social-Dating-CMS 17.9.1 in the user profile Description field.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/ph7software/ph7builder
Introduced in:
0No fixed version published yet for ph7software/ph7builder (composer). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-63644[ADVISORY]
- https://drive.google.com/drive/folders/1mYDvUTnlTPCGTB-7tHD3pmu_wHtlMVRP[WEB]
- https://github.com/pH7Software/pH7-Social-Dating-CMS[PACKAGE]
- https://medium.com/@rudranshsinghrajpurohit/cve-2025-63644-stored-cross-site-scripting-xss-vulnerability-in-ph7-social-dating-cms-23ed0e7eb853[WEB]