CVE-2025-63709 is a stored Cross-Site Scripting (XSS) vulnerability affecting SourceCodester Simple To-Do List System 1.0. An authenticated attacker can inject malicious HTML/JavaScript into the "Add Tasks" input, which is then executed in the browser of any user viewing the task. This vulnerability has a CVSS score of 5.4 (Medium), indicating a low attack complexity and requiring user interaction, with potential for limited confidentiality and integrity impact. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is it listed in CISA's KEV catalog, suggesting it is not being actively exploited. Community discussion and media coverage are minimal, aligning with the typical low attention for most CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:chuck24:simple_to-do_list_system:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.