Vulnerabilities
4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-25349 | All versions of package materialize-css are vulnerable to Cross-site Scripting (XSS) due to improper escape of user input (such as <not-a-tag />) that is being All versions of package materialize-css are vulnerable to Cross-site Scripting (XSS) due to improper escape of user input (such as <not-a-tag />) that is being parsed as HTML/JavaScript, and inserted into the Document Object Model (DOM). This vulnerability can be exploited when the user-input is provided to the autocomplete component. NVD description · AI analysis pending | 5.4 | 1% | PoC ×2 |
| — | |
| CVE-2019-11002 | In Materialize through 1.0.0, XSS is possible via the Tooltip feature. In Materialize through 1.0.0, XSS is possible via the Tooltip feature. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — |