
CVE-2025-63260 SyncFusion 30.1.37 is vulnerable to Cross Site Scripting (XSS) via the Document-Editor reply to comment field and Chat-UI Chat message. https://www.cve.org/CVERecord?id=CVE-2025-63260
Post summary
The post announces CVE-2025-63260 as a Cross Site Scripting flaw affecting SyncFusion 30.1.37’s Document-Editor reply field and Chat-UI messages, but it does not provide any PoC, exploit code, patch, or evidence of active exploitation.
