Cross Site Scripting Vulnerability in SyncFusion Document Editor and Chat-UI
CVE-2025-63260
5.4MEDIUM
What is CVE-2025-63260?
The SyncFusion version 30.1.37 is exposed to a Cross Site Scripting (XSS) vulnerability. This flaw allows malicious actors to inject arbitrary scripts into the Document Editor's reply to comment field and the Chat-UI's chat message functionality. If exploited, this could enable attackers to execute harmful scripts in the context of a user's browser, potentially compromising user data and session integrity.
