Description
billboard.js before 3.18.0 allows an attacker to execute malicious JavaScript due to improper sanitization during chart option binding.
Recommendation
Update the billboard.js package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.18.0
- Patched version(s): 3.18.0
References
Could your website be exposed too?
SmartScanner can check your website for billboard.js is vulnerable to XSS during chart option binding and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Svelte vulnerable to XSS during SSR with contenteditable `bind:innerText` and `bind:textContent` - CVE-2026-27901
- Nuxt OG Image is vulnerable to reflected XSS via query parameter injection into HTML attributes - CVE-2026-34405
- Trix is vulnerable to XSS through JSON deserialization bypass in drag-and-drop (Level0InputController) - CVE-2026-73427
- wetty vulnerable to DOM XSS via file-download filename - CVE-2026-49864
You might also like:
See something that needs correcting? Let us knowUpdated January 28, 2026


