uikit@3.24.2-dev.585805426 vulnerabilities

UIkit is a lightweight and modular front-end framework for developing fast and powerful web interfaces.

Direct Vulnerabilities

Known vulnerabilities in the uikit package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Cross-site Scripting (XSS)

uikit is a lightweight and modular front-end framework for developing fast and powerful web interfaces.

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the data-caption attribute due to insufficient input sanitisation and output escaping. An attacker can execute arbitrary web scripts in the context of another user by injecting malicious content as a user with Contributor-level access or higher.

Note:

The underlying 'uikit' package behavior is exposed by other packages such as 'Element Pack Addons' for Elementor plugin for WordPress. 'Element Pack Addons' has mitigated the issue in version 8.1.0.

How to fix Cross-site Scripting (XSS)?

There is no fixed version for uikit.

>=2.18.0