Description
bracket-template suffers from reflected XSS possible when variable passed via GET parameter is used in template
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.1.5
References
Related Issues
- Pandao editor.md vulnerable to XSS in IMG attributes - CVE-2018-16330
- Enhanced Image plugin for CKEditor is vulnerable to Cross-site scripting (XSS) - CVE-2018-9861
- Nuxt OG Image is vulnerable to reflected XSS via query parameter injection into HTML attributes - CVE-2026-34405
- Formstone Vulnerable to Reflected XSS - CVE-2020-26768
You might also like:
- Tags:
- npm
- bracket-template
Anything's wrong? Let us know Last updated on September 11, 2023


