Cross-site Scripting Vulnerability in YouTube Showcase by Emarket-design
CVE-2025-58915
6.5MEDIUM
What is CVE-2025-58915?
The YouTube Showcase plugin by Emarket-design contains a vulnerability that allows for Cross-site Scripting (XSS). This issue arises due to improper neutralization of user input during the generation of web pages. Exploiting this vulnerability can result in the execution of arbitrary JavaScript code in the context of the victim's browser, leading to session hijacking or unauthorized actions on behalf of users. The affected versions span from an unspecified initial version to 3.5.0.
Affected Version(s)
YouTube Showcase <= 3.5.0
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Muhammad Yudha - DJ (Patchstack Bug Bounty Program)