billboard.js is vulnerable to Cross-site Scripting (XSS)
75
High Risk
Affected versions of the package are vulnerable to multiple cross-site scripting issues due to insufficient input validation and output encoding at several points in the codebase. User-controlled data can be rendered without proper sanitization in different execution paths, allowing injected scripts to execute in a victim’s browser. The fix addresses these issues by tightening validation and applying appropriate escaping at all affected locations, ensuring untrusted input is safely handled throughout the application.
You are affected if you are using a version that falls within the vulnerable range.
billboard.js is vulnerable to Cross-site Scripting (XSS) in versions 0.0.1 - 3.17.4.
Upgrade the billboard.js library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant