ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-25349
All versions of package materialize-css are vulnerable to Cross-site Scripting (XSS) due to improper escape of user input (such as <not-a-tag />) that is being

All versions of package materialize-css are vulnerable to Cross-site Scripting (XSS) due to improper escape of user input (such as <not-a-tag />) that is being parsed as HTML/JavaScript, and inserted into the Document Object Model (DOM). This vulnerability can be exploited when the user-input is provided to the autocomplete component.

NVD description · AI analysis pending
5.41% PoC ×2
  • materializecss materialize
CVE-2019-11002
+2 in the same advisory: …11004 …11003
In Materialize through 1.0.0, XSS is possible via the Tooltip feature.

In Materialize through 1.0.0, XSS is possible via the Tooltip feature.

NVD description · AI analysis pending
6.1<1% PoC
  • materializecss materialize