Cross-Site Scripting Vulnerability in Sourcecodester AI-Powered To-Do List App
CVE-2025-63638
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 7 November 2025
What is CVE-2025-63638?
The Sourcecodester AI-Powered To-Do List App version 1.0 is susceptible to a Cross-Site Scripting (XSS) issue. This vulnerability occurs within the 'Task Title' and 'Description (Optional)' fields during task creation. Attackers can exploit this flaw to inject arbitrary HTML or JavaScript code. When users click the 'Add Task' button, the inserted code executes in their browsers, potentially compromising user data and session security. It is crucial for users and administrators to be aware of this vulnerability and take necessary precautions to mitigate potential threats.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
