Tool for transforming styles with JS plugins
90%
Total Score
100
100
100
100
50
| Title | Versions | Severity |
|---|---|---|
CVE-2026-41305 postcss is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 8.5.10. | 0.0.0 - 8.5.10 | Medium |
CVE-2023-44270 postcss is vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in versions 0.0.0 - 8.4.31. | 0.0.0 - 8.4.31 | Medium |
CVE-2021-23382 postcss is vulnerable to Uncontrolled Resource Consumption in versions 8.0.0 - 8.2.13 and 0.0.0 - 7.0.36. | 0.0.0 - 7.0.368.0.0 - 8.2.13 | Medium |
CVE-2021-23368 postcss is vulnerable to Uncontrolled Resource Consumption in versions 7.0.0 - 7.0.36 and 8.0.0 - 8.2.10. | 7.0.0 - 7.0.368.0.0 - 8.2.10 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
nanoid Version ^3.3.12 | — | — |
picocolors Version ^1.1.1 | — | — |
source-map-js Version ^1.2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant