← Vulnerability feed

Vulnerability record · CVE-2025-60378 · published 10 October 2025

CVE-2025-60378: Fairsketch rise ultimate project manager cross-site scripting vulnerability

Fairsketch · Rise Ultimate Project Manager

Stored HTML injection in RISE Ultimate Project Manager & CRM allows authenticated users to inject arbitrary HTML into invoices and messages. Injected content renders in emails, PDFs, and messaging/chat modules sent to clients or team members, enabling phishing, credential theft, and business email compromise. Automated recurring invoices and messaging amplify the risk by distributing malicious content to multiple recipients.

8.1 CVSS 3.1 High EPSS 1.1% · top 36.3% CWE-79 · Cross-site scripting
8.1CVSS 3.1 base score
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References, 1 tagged exploit
5 Jul 2026Last modified by NVD

Description

Stored HTML injection in RISE Ultimate Project Manager & CRM allows authenticated users to inject arbitrary HTML into invoices and messages. Injected content renders in emails, PDFs, and messaging/chat modules sent to clients or team members, enabling phishing, credential theft, and business email compromise. Automated recurring invoices and messaging amplify the risk by distributing malicious content to multiple recipients.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/ajansha/CVE-2025-60378 ExploitMitigationThird Party Advisory

Track CVE-2025-60378 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-17999Fairsketch rise ultimate project manager sql injection vulnerabilitySQL injection vulnerability in RISE Ultimate Project Manager 1.9 allows remote attackers to execute arbitrary SQL commands via the search parameter t…EPSS 3.3%6.9CVE-2024-0545Fairsketch rise ultimate project manager open redirect vulnerabilityA vulnerability classified as problematic was found in CodeCanyon RISE Ultimate Project Manager 3.5.3. This vulnerability affects unknown code of the…EPSS 0.48%6.5CVE-2025-63293Fairsketch rise ultimate project manager missing authorization vulnerabilityFairSketch Rise Ultimate Project Manager & CRM 3.9.4 is vulnerable to Insecure Permissions. A remote authenticated user can append comments or upload…EPSS 0.35%6.1CVE-2025-56807Fairsketch rise ultimate project manager cross-site scripting vulnerabilityA cross-site scripting (XSS) vulnerability in FairSketch RISE Ultimate Project Manager & CRM 3.9.4 allows an administrator to store a JavaScript payl…EPSS 0.23%5.4CVE-2017-11181Fairsketch rise ultimate project manager cross-site scripting vulnerabilityIn Rise Ultimate Project Manager v1.8, XSS vulnerabilities were found in the Messaging section. Subject and Message fields are vulnerable.EPSS 0.66%5.4CVE-2017-11182Fairsketch rise ultimate project manager cross-site scripting vulnerabilityIn Rise Ultimate Project Manager v1.8, XSS vulnerabilities were found in the My Profile section. All input fields are vulnerable.EPSS 0.80%5.3CVE-2025-3855Fairsketch rise ultimate project manager vulnerabilityA vulnerability was found in CodeCanyon RISE Ultimate Project Manager 3.8.2 and classified as problematic. Affected by this issue is some unknown fun…EPSS 0.48%5.3CVE-2024-8945Fairsketch rise ultimate project manager sql injection vulnerabilityA vulnerability has been found in CodeCanyon RISE Ultimate Project Manager 3.7.0 and classified as critical. This vulnerability affects unknown code …EPSS 16%

Source: NIST National Vulnerability Database (record CVE-2025-60378), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.