Cross-site Scripting Vulnerability in PlayerJS by PlayerJS
CVE-2025-27330
6.5MEDIUM
What is CVE-2025-27330?
PlayerJS is susceptible to a Cross-site Scripting (XSS) vulnerability that arises due to improper neutralization of input during web page generation. This flaw enables attackers to execute arbitrary JavaScript in the user’s browser, potentially leading to data theft or unauthorized actions. Affected versions of PlayerJS include those from n/a up to 2.23.
Affected Version(s)
PlayerJS <= 2.23