CVE-2025-23854: Yesstreamingdev Shoutcast And Icecast HTML5 Web Radio Player By Yesstreaming.com

Medium severity, CVSS 5.9. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yesstreamingdev Shoutcast and Icecast HTML5 Web Radio Player by YesStreaming.com shoutcast-and-icecast-html5-web-radio-player-by-yesstreaming-com allows Stored XSS.This issue affects Shoutcast and Icecast HTML5 Web Radio Player by YesStreaming.com: from n/a through <= 3.3.

Affected products

  • Yesstreamingdev Shoutcast And Icecast HTML5 Web Radio Player By Yesstreaming.com: up to and including 3.3

Published 2025-01-16. Last modified 2026-06-17.