layui@2.9.10 vulnerabilities

Classic modular Front-End UI library

Direct Vulnerabilities

Known vulnerabilities in the layui package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Cross-site Scripting (XSS)

layui is an is a front-end UI framework written using its own module specifications. It follows the native HTML/CSS/JS writing and organization form.

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the img tags with unsanitized name attributes. An attacker can manipulate web page content and execute arbitrary scripts by injecting malicious HTML elements.

How to fix Cross-site Scripting (XSS)?

Upgrade layui to version 2.9.17 or higher.

<2.9.17