magnific-popup is vulnerable to Cross-Site Scripting
40
Medium Risk
Affected versions of magnific-popup are vulnerable to Cross-site Scripting (XSS) if users are allowed to include (limited) HTML content (from editors like CKEditor) in the pop-up.
You are affected if you use a vulnerable version of magnific-popup and allow limited HTML content (from editors like CKEditor) in the pop-up.
magnific-popup is vulnerable to Cross-Site Scripting in versions 0.9.6 - 1.1.0.
Upgrade magnific-popup to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant