Radzen.Blazor is vulnerable to Cross-Site Scripting (XSS)
50
Medium Risk
Affected versions of this package are vulnerable to cross-site scripting (XSS) attacks due to improper handling of MarkupStrings in components. To mitigate this, all MarkupStrings have been removed.
You are affected if you are using a version that falls within the vulnerable range.
Radzen.Blazor is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 6.3.4.
Upgrade the Radzen.Blazor library to the patch version. Note: some breaking changes have been introduced (compared to 6.3.x). Unicode symbols for icons must now be used directly as characters rather than HTML entities (e.g., replace <RadzenIcon Icon=""/> with <RadzenIcon Icon="@("")"/>). Additionally, dialog titles no longer support HTML content—developers should use DialogContent instead.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant