Description
In Dojo Toolkit before 1.14.0, there is unescaped string injection in dojox/Grid/DataGrid.
Recommendation
Update the dojox package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.14.0
- Patched version(s): 1.14.0
References
- GHSA-84cm-x2q5-8225
- dojotoolkit.org
- lists.debian.org
- CVE-2018-15494
- CWE-116
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- defuddle vulnerable to XSS via unescaped string interpolation in _findContentBySchemaText image tag - CVE-2026-30830
- Joplin Vulnerable to Cross-site Scripting in Note Content - CVE-2018-1000534
- OneUptime ClickHouse vulnerable to SQL Injection via unvalidated column identifiers in sort, select, and groupBy paramet - CVE-2026-33142
- @siteboon/claude-code-ui is Vulnerable to Shell Command Injection in Git Routes - CVE-2026-31861
You might also like:
- Tags:
- npm
- dojox
Anything's wrong? Let us know Last updated on September 27, 2023


