CVE-2025-25960

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Feb 20, 2025
Updated: Feb 21, 2025
CWE ID 79

Summary

CVE-2025-25960 is a Cross-Site Scripting (XSS) vulnerability affecting phpcmsv9 version 9.6.3. An attacker can exploit this flaw in the member center of the background administrator's menu interface to inject malicious scripts, potentially escalating privileges and gaining unauthorized access to sensitive data. This vulnerability poses a significant risk to websites using the affected version of phpcmsv9 and requires immediate attention and patching to mitigate the threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share