CVE-2025-63588
HIGHCMSimpleXH - XSS
Title source: llmDescription
An unauthenticated reflected cross-site scripting vulnerability in the query handling of CMSimpleXH allows remote attackers to inject and execute arbitrary JavaScript in a victim's browser via a crafted request (e.g., a maliciously crafted POST login). Successful exploitation may lead to theft of session cookies, credential disclosure, or other client-side impacts.
Exploits (1)
Scores
CVSS v3
7.1
EPSS
0.0005
EPSS Percentile
15.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
cmsimple-xh/cmsimple_xh
1.8.0
Published
Nov 06, 2025
Tracked Since
Feb 18, 2026