Junglewise Threat Intelligence

CVE-2025-63520: FeehiCMS is vulnerable to cross-site scripting via the id parameter of the User Update function

CVE-2025-63520 · Severity: low · CVSS 3.1 · Published 2025-12-01

Technologies: feehi/feehicms (Packagist). Vendors: Packagist.

Executive brief

FeehiCMS is vulnerable to cross-site scripting via the id parameter of the User Update function

Affected products

  • Packagist feehi/feehicms

Related threats