Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

redhat логотип

CVE-2026-27122

6 месяцев назад

svelte performance oriented web framework. Prior to 5.51.5, when using <svelte:element this={tag}> in server-side rendering, the provided tag name is not validated or sanitized before being emitted into the HTML output. If the tag string contains unexpected characters, it can result in HTML injection in the SSR output. Client-side rendering is not affected. This vulnerability is fixed in 5.51.5.

CVSS3: 5.6
EPSS: Низкий
nvd логотип

CVE-2026-27122

6 месяцев назад

svelte performance oriented web framework. Prior to 5.51.5, when using <svelte:element this={tag}> in server-side rendering, the provided tag name is not validated or sanitized before being emitted into the HTML output. If the tag string contains unexpected characters, it can result in HTML injection in the SSR output. Client-side rendering is not affected. This vulnerability is fixed in 5.51.5.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-m56q-vw4c-c2cp

6 месяцев назад

Svelte SSR does not validate dynamic element tag names in `<svelte:element>`

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-27122

svelte performance oriented web framework. Prior to 5.51.5, when using <svelte:element this={tag}> in server-side rendering, the provided tag name is not validated or sanitized before being emitted into the HTML output. If the tag string contains unexpected characters, it can result in HTML injection in the SSR output. Client-side rendering is not affected. This vulnerability is fixed in 5.51.5.

CVSS3: 5.6
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-27122

svelte performance oriented web framework. Prior to 5.51.5, when using <svelte:element this={tag}> in server-side rendering, the provided tag name is not validated or sanitized before being emitted into the HTML output. If the tag string contains unexpected characters, it can result in HTML injection in the SSR output. Client-side rendering is not affected. This vulnerability is fixed in 5.51.5.

CVSS3: 5.4
0%
Низкий
6 месяцев назад
github логотип
GHSA-m56q-vw4c-c2cp

Svelte SSR does not validate dynamic element tag names in `<svelte:element>`

0%
Низкий
6 месяцев назад

Уязвимостей на страницу