Cross-site Scripting Vulnerability in Sonaar MP3 Audio Player by Sonaar
CVE-2026-104673

6.5MEDIUM

What is CVE-2026-104673?

A Cross-site Scripting (XSS) vulnerability exists in the Sonaar MP3 Audio Player for Music, Radio & Podcast, allowing malicious actors to inject and execute scripts in the user's browser. This issue affects all versions of the product up to and including 5.14.2, which may put users at risk of unintended actions or data exposure. Proper input validation and output encoding are recommended to mitigate such threats.

Affected Version(s)

MP3 Audio Player for Music, Radio & Podcast by Sonaar 0 <= 5.14.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack)
.