
Explore packages and vulnerabilities by …
Operating system
Infrastructure as Code
Vulnerabilities from the last week
Cross-site Scripting (XSS)
trix is a Rich Text Editor.
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the data-trix-serialized-attributes attribute bypassing the DOMPurify sanitizer. An attacker can execute arbitrary JavaScript code within the user's session by crafting HTML containing a malicious payload in this attribute, potentially leading to unauthorized actions or disclosure of sensitive information when the content is rendered.
Cross-site Scripting (XSS)
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the upload of .prologue.html file when a crafted URL is accessed. An attacker can execute arbitrary JavaScript in the context of another user's session by uploading a malicious .prologue.html file and tricking a victim into clicking a specially crafted link.
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
Affected versions of this package are vulnerable to Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') via JEXL dependency. An attacker can execute arbitrary commands, access sensitive data, or disrupt service by submitting specially crafted input.
Recent vulnerabilities disclosed by Snyk
- C
Improper Handling of Case Sensitivity in @whyour/qinglong (npm)- C
Remote Code Execution (RCE) in @whyour/qinglong (npm)- M
Cross-site Scripting (XSS) in spin.js (npm)- C
Arbitrary Code Injection in es-toolkit (npm)- M
Cross-site Scripting (XSS) in mailparser (npm)
Snyk security
researchers
have disclosed
3473
vulnerabilities
About Snyk dependencies vulnerability database
Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit.




