i18next
11 known vulnerabilities · 0 critical · 0 high
Malicious code in @ensdomains/vite-plugin-i18next-loader (npm)
Malicious code in prettier-plugin-kimi-i18next (npm)
i18next-http-middleware: Prototype pollution and path traversal via user-controlled language and namespace parameters
i18nextify has DOM XSS via javascript:/data: URL schemes in translated href/src attributes
i18next-fs-backend: Path traversal via unsanitised lng/ns allows arbitrary file read/overwrite
i18next-http-middleware: HTTP response splitting and DoS via unsanitised Content-Language header
i18next-locize-backend has URL Injection via Unsanitized Path Parameters
i18next-http-backend has Path Traversal & URL Injection via Unsanitised lng/ns
Malicious code in @sev-ui-verse/i18next-config (npm)