layui@2.7.0 vulnerabilities

Classic modular Front-End UI library

  • latest version

    2.9.20

  • latest non vulnerable version

  • first published

    8 years ago

  • latest version published

    19 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the layui package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Cross-site Scripting (XSS)

    layui is an is a front-end UI framework written using its own module specifications. It follows the native HTML/CSS/JS writing and organization form.

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the img tags with unsanitized name attributes. An attacker can manipulate web page content and execute arbitrary scripts by injecting malicious HTML elements.

    How to fix Cross-site Scripting (XSS)?

    Upgrade layui to version 2.9.17 or higher.

    <2.9.17
    • C
    Cross-site Scripting (XSS)

    layui is an is a front-end UI framework written using its own module specifications. It follows the native HTML/CSS/JS writing and organization form.

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the data-content parameter.

    How to fix Cross-site Scripting (XSS)?

    Upgrade layui to version 2.7.5 or higher.

    <2.7.5
    • L
    Cross-site Scripting (XSS)

    layui is an is a front-end UI framework written using its own module specifications. It follows the native HTML/CSS/JS writing and organization form.

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the title parameter of checkboxes or other objects.

    How to fix Cross-site Scripting (XSS)?

    Upgrade layui to version 2.8.0 or higher.

    <2.8.0