Description
In Dojo Toolkit before 1.14.0, there is unescaped string injection in dojox/Grid/DataGrid.
Recommendation
Update the dojox package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.14.0
- Patched version(s): 1.14.0
References
Could your website be exposed too?
SmartScanner can check your website for dojox vulnerable to unescaped string injection and gives you actionable findings to investigate.
Start a free scanRelated Issues
- defuddle vulnerable to XSS via unescaped string interpolation in _findContentBySchemaText image tag - CVE-2026-30830
- Joplin Vulnerable to Cross-site Scripting in Note Content - CVE-2018-1000534
- OneUptime ClickHouse vulnerable to SQL Injection via unvalidated column identifiers in sort, select, and groupBy paramet - CVE-2026-33142
- @siteboon/claude-code-ui is Vulnerable to Shell Command Injection in Git Routes - CVE-2026-31861
You might also like:
See something that needs correcting? Let us knowUpdated September 27, 2023


