|
4482 | 4482 | "https://github.com/cure53/DOMPurify/commit/26e1d69ca7f769f5c558619d644d90dd8bf26ebc", |
4483 | 4483 | "https://github.com/cure53/DOMPurify" |
4484 | 4484 | ] |
| 4485 | + }, |
| 4486 | + { |
| 4487 | + "atOrAbove": "0", |
| 4488 | + "below": "3.2.4", |
| 4489 | + "cwe": [ |
| 4490 | + "CWE-79" |
| 4491 | + ], |
| 4492 | + "severity": "medium", |
| 4493 | + "identifiers": { |
| 4494 | + "summary": "DOMPurify allows Cross-site Scripting (XSS)", |
| 4495 | + "CVE": [ |
| 4496 | + "CVE-2025-26791" |
| 4497 | + ], |
| 4498 | + "githubID": "GHSA-vhxf-7vqr-mrjg" |
| 4499 | + }, |
| 4500 | + "info": [ |
| 4501 | + "https://github.com/advisories/GHSA-vhxf-7vqr-mrjg", |
| 4502 | + "https://nvd.nist.gov/vuln/detail/CVE-2025-26791", |
| 4503 | + "https://github.com/cure53/DOMPurify/commit/d18ffcb554e0001748865da03ac75dd7829f0f02", |
| 4504 | + "https://ensy.zip/posts/dompurify-323-bypass", |
| 4505 | + "https://github.com/cure53/DOMPurify", |
| 4506 | + "https://github.com/cure53/DOMPurify/releases/tag/3.2.4", |
| 4507 | + "https://nsysean.github.io/posts/dompurify-323-bypass" |
| 4508 | + ] |
4485 | 4509 | } |
4486 | 4510 | ], |
4487 | 4511 | "extractors": { |
|
6142 | 6166 | "https://github.com/axios/axios/releases/tag/v1.7.4", |
6143 | 6167 | "https://jeffhacks.com/advisories/2024/06/24/CVE-2024-39338.html" |
6144 | 6168 | ] |
| 6169 | + }, |
| 6170 | + { |
| 6171 | + "atOrAbove": "0", |
| 6172 | + "below": "1.8.2", |
| 6173 | + "cwe": [ |
| 6174 | + "CWE-918" |
| 6175 | + ], |
| 6176 | + "severity": "high", |
| 6177 | + "identifiers": { |
| 6178 | + "summary": "axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL", |
| 6179 | + "CVE": [ |
| 6180 | + "CVE-2025-27152" |
| 6181 | + ], |
| 6182 | + "githubID": "GHSA-jr5f-v2jv-69x6" |
| 6183 | + }, |
| 6184 | + "info": [ |
| 6185 | + "https://github.com/advisories/GHSA-jr5f-v2jv-69x6", |
| 6186 | + "https://github.com/axios/axios/security/advisories/GHSA-jr5f-v2jv-69x6", |
| 6187 | + "https://nvd.nist.gov/vuln/detail/CVE-2025-27152", |
| 6188 | + "https://github.com/axios/axios/issues/6463", |
| 6189 | + "https://github.com/axios/axios/commit/fb8eec214ce7744b5ca787f2c3b8339b2f54b00f", |
| 6190 | + "https://github.com/axios/axios", |
| 6191 | + "https://github.com/axios/axios/releases/tag/v1.8.2" |
| 6192 | + ] |
6145 | 6193 | } |
6146 | 6194 | ], |
6147 | 6195 | "extractors": { |
|
7128 | 7176 | "https://froala.com/wysiwyg-editor/changelog/#4.1.4", |
7129 | 7177 | "https://github.com/advisories/GHSA-hvpq-7vcc-5hj5" |
7130 | 7178 | ] |
| 7179 | + }, |
| 7180 | + { |
| 7181 | + "atOrAbove": "0", |
| 7182 | + "below": "4.3.1", |
| 7183 | + "cwe": [ |
| 7184 | + "CWE-79" |
| 7185 | + ], |
| 7186 | + "severity": "medium", |
| 7187 | + "identifiers": { |
| 7188 | + "summary": "Froala WYSIWYG editor allows cross-site scripting (XSS)", |
| 7189 | + "CVE": [ |
| 7190 | + "CVE-2024-51434" |
| 7191 | + ], |
| 7192 | + "githubID": "GHSA-549p-5c7f-c5p4" |
| 7193 | + }, |
| 7194 | + "info": [ |
| 7195 | + "https://github.com/advisories/GHSA-549p-5c7f-c5p4", |
| 7196 | + "https://nvd.nist.gov/vuln/detail/CVE-2024-51434", |
| 7197 | + "https://georgyg.com/home/froala-wysiwyg-editor---xss-cve-2024-51434", |
| 7198 | + "https://github.com/froala/wysiwyg-editor" |
| 7199 | + ] |
7131 | 7200 | } |
7132 | 7201 | ], |
7133 | 7202 | "extractors": { |
|
0 commit comments