CVE-2025-63260: Syncfusion

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

SyncFusion 30.1.37 is vulnerable to Cross Site Scripting (XSS) via the Document-Editor reply to comment field and Chat-UI Chat message.

Affected products

Published 2026-03-20. Last modified 2026-07-05.