Security Advisory

CVE-2025-27005

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-01-22 16:51:38
Last updated 2026-04-01 14:07:10
Assigner Patchstack
State PUBLISHED

Description

Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability in LambertGroup HTML5 Video Player lbg-vp2-html5-bottom allows Reflected XSS.This issue affects HTML5 Video Player: from n/a through <= 5.3.5.