org.webjars:layui@2.5.4 vulnerabilities

  • latest version

    2.9.10

  • first published

    8 years ago

  • latest version published

    6 months ago

  • licenses detected

  • package manager

Direct Vulnerabilities

Known vulnerabilities in the org.webjars:layui package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Cross-site Scripting (XSS)

org.webjars:layui is an is a front-end UI framework written using its own module specifications. It follows the native HTML/CSS/JS writing and organization form.

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the img tags with unsanitized name attributes. An attacker can manipulate web page content and execute arbitrary scripts by injecting malicious HTML elements.

How to fix Cross-site Scripting (XSS)?

Upgrade org.webjars:layui to version 2.9.18 or higher.

[,2.9.18)
  • C
Cross-site Scripting (XSS)

org.webjars:layui is an is a front-end UI framework written using its own module specifications. It follows the native HTML/CSS/JS writing and organization form.

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the data-content parameter.

How to fix Cross-site Scripting (XSS)?

Upgrade org.webjars:layui to version 2.7.6 or higher.

[,2.7.6)
  • L
Cross-site Scripting (XSS)

org.webjars:layui is an is a front-end UI framework written using its own module specifications. It follows the native HTML/CSS/JS writing and organization form.

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the title parameter of checkboxes or other objects.

How to fix Cross-site Scripting (XSS)?

Upgrade org.webjars:layui to version 2.8.12 or higher.

[,2.8.12)
  • M
Cross-site Scripting (XSS)

org.webjars:layui is an is a front-end UI framework written using its own module specifications. It follows the native HTML/CSS/JS writing and organization form.

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via table rendering.

How to fix Cross-site Scripting (XSS)?

Upgrade org.webjars:layui to version 2.6.8 or higher.

[0,2.6.8)