CVE-2025-63260

Published: Mar 20, 2026 Last Modified: Mar 20, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

SyncFusion 30.1.37 is vulnerable to Cross Site Scripting (XSS) via the Document-Editor reply to comment field and Chat-UI Chat message.

https://pentest-tools.com/PTT-2025-023-Multiple-Stored-XSS.pdf
http://syncfusion.com