Cross-Site Scripting in Top Flash Embed by Nikos M. Top
CVE-2025-23841
6.5MEDIUM
What is CVE-2025-23841?
A vulnerability exists in the Top Flash Embed plugin by Nikos M. Top, allowing attackers to exploit improper input handling during web page generation, leading to Stored Cross-Site Scripting (XSS). This issue affects all versions of Top Flash Embed up to 0.3.4, enabling potential unauthorized access to sensitive user data and site manipulation.
Affected Version(s)
Top Flash Embed <= 0.3.4