Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-16516 | Chrome PHP is missing encoding in `CssSelector` |
Github GHSA |
GHSA-3432-fmrf-7vmh | Chrome PHP is missing encoding in `CssSelector` |
Fri, 30 May 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 30 May 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Chrome PHP allows users to start playing with chrome/chromium in headless mode from PHP. Prior to version 1.14.0, CSS Selector expressions are not properly encoded, which can lead to XSS (cross-site scripting) vulnerabilities. This is patched in v1.14.0. As a workaround, users can apply encoding manually to their selectors if they are unable to upgrade. | |
| Title | Chrome PHP is missing encoding in `CssSelector` | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-05-30T20:39:45.976Z
Reserved: 2025-05-27T20:14:34.296Z
Link: CVE-2025-48883
Updated: 2025-05-30T20:39:41.312Z
Status : Deferred
Published: 2025-05-30T19:15:29.540
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-48883
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA