Количество 2
Количество 2
CVE-2021-23784
больше 4 лет назад
This affects the package tempura before 0.4.0. If the input to the esc function is of type object (i.e an array) it is returned without being escaped/sanitized, leading to a potential Cross-Site Scripting vulnerability.
CVSS3: 5.4
EPSS: Низкий
GHSA-w4v7-hwx7-9929
больше 4 лет назад
Cross-site Scripting in tempura
CVSS3: 6.1
EPSS: Низкий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2021-23784 This affects the package tempura before 0.4.0. If the input to the esc function is of type object (i.e an array) it is returned without being escaped/sanitized, leading to a potential Cross-Site Scripting vulnerability. | CVSS3: 5.4 | 0% Низкий | больше 4 лет назад | |
GHSA-w4v7-hwx7-9929 Cross-site Scripting in tempura | CVSS3: 6.1 | 0% Низкий | больше 4 лет назад |
Уязвимостей на страницу
20