XSS Vulnerability in Chrome PHP Affects Multiple Versions
CVE-2025-48883
5.3MEDIUM
What is CVE-2025-48883?
Chrome PHP prior to version 1.14.0 contains a vulnerability that allows attackers to exploit improper encoding of CSS Selector expressions. This can lead to Cross-Site Scripting (XSS) attacks, potentially compromising user data and site integrity. Users are encouraged to upgrade to version 1.14.0 or later to mitigate this risk. Alternatively, if upgrading is not feasible, manually applying encoding to selectors can help prevent exploitation.
Affected Version(s)
chrome < 1.14.0