billboard.js is vulnerable to Cross-site Scripting (XSS)
75
High Risk
Affected versions of the package are vulnerable to multiple cross-site scripting issues due to insufficient input validation and output encoding at several points in the codebase. User-controlled data can be rendered without proper sanitization in different execution paths, allowing injected scripts to execute in a victim’s browser. The fix addresses these issues by tightening validation and applying appropriate escaping at all affected locations, ensuring untrusted input is safely handled throughout the application.
You are affected if you are using a version that falls within the vulnerable range.
billboard.js is vulnerable to Cross-site Scripting (XSS) in versions 0.0.1 - 3.17.4.
Upgrade the billboard.js library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant