Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YesStreaming.com Shoutcast and Icecast Internet Radio Hosting Shoutcast and Icecast HTML5 Web Radio Player by YesStreaming.com allows Stored XSS.This issue affects Shoutcast and Icecast HTML5 Web Radio Player by YesStreaming.com: from n/a through 3.3.
CVE ID: CVE-2025-23854
CVSS Base Severity: MEDIUM
CVSS Base Score: 5.9
Vendor: YesStreaming.com Shoutcast and Icecast Internet Radio Hosting
Product: Shoutcast and Icecast HTML5 Web Radio Player by YesStreaming.com
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 11.64% (scored less or equal to compared to others)
EPSS Date: 2025-02-14 (when was this score calculated)