Executive brief
FeehiCMS is vulnerable to cross-site scripting via the id parameter of the User Update function
Affected products
- Packagist feehi/feehicms
Junglewise Threat Intelligence
CVE-2025-63520 · Severity: low · CVSS 3.1 · Published 2025-12-01
Technologies: feehi/feehicms (Packagist). Vendors: Packagist.
FeehiCMS is vulnerable to cross-site scripting via the id parameter of the User Update function