swiper is vulnerable to Cross-site Scripting (XSS)
28
Low Risk
Affected versions of this package do not support the TrustedTypes API, which is designed to prevent DOM-based injection attacks such as Cross-Site Scripting (XSS). When used in environments enforcing TrustedTypes, Swiper.js fails to wrap dynamic HTML assignments with innerHTML. An attacker could exploit this by injecting malicious payloads into Swiper-controlled elements (e.g., slides, pagination, or navigation) if the application passes unsanitized user input to Swiper's initialization or content methods, effectively bypassing protections and enabling XSS attacks.
You are affected if you are using a version that falls within the vulnerable range.
swiper is vulnerable to Cross-site Scripting (XSS) in versions 10.0.0 - 11.2.6.
Upgrade the swiper library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant