2.5.0
10 years ago
2 years ago
Known vulnerabilities in the semantic-ui-search package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
semantic-ui-search is a pre-compiled search files using the default themes. This is intended for use in projects that do not need all the bells and whistles of Semantic UI, and want to keep file size to a minimum. Affected versions of this package are vulnerable to Cross-site Scripting (XSS). Lack of output encoding on the selection dropdown user additions and search response values can lead to user input being executed as JavaScript instead of plaintext. This is due to the The remediation to this vulnerability has applied to fomantic-u, a community fork of the popular Semantic-UI framework. How to fix Cross-site Scripting (XSS)? There is no fixed version for | * |