OsVault/npm/ip
npm22 critical

ip

1000 known vulnerabilities · 22 critical · 61 high

CVE-2023-42282CRITICAL

NPM IP package incorrectly identifies some private IP addresses as public

Published Feb 8, 2024
CVE-2024-29415HIGH

ip SSRF improper categorization in isPublic

Published Jun 2, 2024
MAL-2024-8639

Malicious code in @diotoborg/soluta-numquam-ipsam (npm)

Published Sep 2, 2024
MAL-2024-8643

Malicious code in @diotoborg/suscipit-amet (npm)

Published Sep 2, 2024
CVE-2021-23398MEDIUM

Cross-site scripting in react-bootstrap-table

Published Dec 10, 2021
CVE-2024-36361MEDIUM

Pug allows JavaScript code execution if an application accepts untrusted input

Published May 24, 2024
MAL-2025-191091

Malicious code in feature-flip (npm)

Published Nov 24, 2025
CVE-2021-23328MEDIUM

Prototype Pollution in iniparserjs

Published Apr 13, 2021
CVE-2026-28452

OpenClaw affected by denial of service through unguarded archive extraction allowing high expansion/resource abuse (ZIP/TAR)

Published Feb 18, 2026
GHSA-3xx2-mqjm-hg9x

Paperclip: Cross-tenant agent API key IDOR in `/agents/:id/keys` routes allows full victim-company compromise

Published Apr 16, 2026
CVE-2023-37299MEDIUM

Joplin Cross-site Scripting vulnerability

Published Jun 30, 2023
CVE-2015-8856MEDIUM

Cross-Site Scripting in serve-index

Published Oct 24, 2017
CVE-2023-6293HIGH

sequelize-typescript Prototype Pollution vulnerability

Published Nov 24, 2023
CVE-2026-4923

path-to-regexp vulnerable to Regular Expression Denial of Service via multiple wildcards

Published Mar 27, 2026
CVE-2016-10652HIGH

prebuild-lwip downloads Resources over HTTP

Published Feb 18, 2019
MAL-2022-5341

Malicious code in pipedrive-embeddable-ringcentral-phone-spa (npm)

Published Jun 20, 2022
CVE-2016-5682MEDIUM

Cross-Site Scripting in swagger-ui

Published Sep 1, 2020
GHSA-47wq-cj9q-wpmp

Paperclip: Cross-tenant agent API token minting via missing assertCompanyAccess on /api/agents/:id/keys

Published Apr 16, 2026
CVE-2017-16016MEDIUM

Cross-Site Scripting in sanitize-html

Published Nov 9, 2018
MAL-2025-191435

Malicious code in tiptap-shadcn-vue (npm)

Published Nov 24, 2025
MAL-2025-191469

Malicious code in bip40 (npm)

Published Nov 25, 2025
CVE-2023-46998MEDIUM

Bootbox.js Cross Site Scripting vulnerability

Published Nov 14, 2023
CVE-2011-4969MEDIUM

jQuery vulnerable to Cross-Site Scripting (XSS)

Published May 14, 2022
CVE-2021-33040MEDIUM

Cross-site Scripting in epubjs

Published Jan 21, 2022
CVE-2017-1000006MEDIUM

Cross Site Scripting (XSS) in plotly.js

Published Oct 24, 2017
CVE-2020-12648MEDIUM

Cross-site scripting vulnerability in TinyMCE

Published Aug 11, 2020
CVE-2023-23636MEDIUM

Jellyfin Web Cross-Site Scripting (XSS) via Playlist Name

Published Feb 3, 2023
CVE-2022-25349MEDIUM

materialize-css vulnerable to cross-site Scripting (XSS) due to improper escape of user input

Published May 3, 2022
GHSA-ccx3-fw7q-rr2r

OpenClaw: Multiple Code Paths Missing Base64 Pre-Allocation Size Checks

Published Apr 9, 2026
CVE-2024-36422MEDIUM

Flowise Cross-site Scripting in api/v1/chatflows/id

Published Aug 5, 2024
CVE-2019-10771MEDIUM

Cross-Site Scripting in iobroker.web

Published Dec 2, 2019
MAL-2024-8261

Malicious code in @diotoborg/dolorum-ipsam (npm)

Published Sep 2, 2024
GHSA-6pfc-6m7w-m8fx

OpenClaw has a gateway exec allowlist allow-always bypass via unregistered /usr/bin/script wrapper

Published Mar 31, 2026
CVE-2020-9038MEDIUM

Cross-site Scripting in Joplin

Published Oct 13, 2020
CVE-2023-1001LOW

vxe-table Cross-site Scripting vulnerability

Published May 24, 2024
CVE-2020-17480MEDIUM

Cross-site scripting vulnerability in TinyMCE

Published Jan 30, 2020
CVE-2024-51434

Froala WYSIWYG editor allows cross-site scripting (XSS)

Published Nov 8, 2024
GHSA-g87j-gm7p-6vw2

Duplicate Advisory: OpenClaw's Node system.run approval hardening wrapper semantic drift can execute unintended local scripts

Published Mar 19, 2026
CVE-2019-14772MEDIUM

Cross-Site Scripting (XSS) in Verdaccio

Published May 29, 2019
CVE-2023-37298MEDIUM

Joplin Cross-site Scripting vulnerability

Published Jun 30, 2023
MAL-2026-3331

Malicious code in lazyhtml-scripts (npm)

Published May 4, 2026
CVE-2022-24728MEDIUM

Cross-site Scripting in CKEditor4

Published Mar 16, 2022
CVE-2022-23494MEDIUM

Cross-site scripting vulnerability in TinyMCE alerts

Published Dec 8, 2022
MAL-2024-8371

Malicious code in @diotoborg/ipsa-deleniti-ab (npm)

Published Sep 2, 2024
CVE-2019-15479MEDIUM

Status Board vulnerable to Cross-Site Scripting before v1.1.82

Published Sep 23, 2019
CVE-2021-40823MEDIUM

matrix-js-sdk can be tricked into disclosing E2EE room keys to a participating homeserver

Published Sep 14, 2021
GHSA-h97f-6pqj-q452

OpenClaw has a IPv6 multicast SSRF classifier bypass

Published Mar 3, 2026
CVE-2026-0621

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

Published Jan 5, 2026
CVE-2021-46871MEDIUM

phoenix_html allows Cross-site Scripting in HEEx class attributes

Published Jan 10, 2023
CVE-2024-29194HIGH

OneUptime Vulnerable to a Privilege Escalation via Local Storage Key Manipulation

Published Mar 25, 2024
CVE-2024-21908MEDIUM

Cross-site scripting vulnerability in TinyMCE

Published Oct 22, 2021
CVE-2025-27109

Solid Lacks Escaping of HTML in JSX Fragments allows for Cross-Site Scripting (XSS)

Published Feb 25, 2025
CVE-2021-32851MEDIUM

Mind-elixir Cross-site Scripting vulnerability

Published Feb 21, 2023
MAL-2025-49356

Malicious code in aes-valid-ipherv (npm)

Published Nov 5, 2025
MAL-2025-5451

Malicious code in plonkscript-docs (npm)

Published Jun 18, 2025
CVE-2022-29230MEDIUM

Potential Cross-site Scripting vulnerability in Hydrogen

Published May 19, 2022
CVE-2024-29271MEDIUM

VvvebJs Reflected Cross-Site Scripting (XSS) vulnerability

Published Mar 22, 2024
CVE-2021-37916MEDIUM

Joplin vulnerable to Cross-site Scripting in notes

Published May 24, 2022
CVE-2022-0087MEDIUM

Reflected cross-site scripting (XSS) vulnerability

Published Jan 12, 2022
CVE-2026-32731

ApostropheCMS has Arbitrary File Write (Zip Slip / Path Traversal) in Import-Export Gzip Extraction

Published Mar 18, 2026
CVE-2023-34245HIGH

@udecode/plate-link does not sanitize URLs to prevent use of the `javascript:` scheme

Published Jun 9, 2023
CVE-2017-16203HIGH

coffe-script is malware

Published Aug 6, 2018
CVE-2026-22176

OpenClaw has a Command Injection via unescaped environment assignments in Windows Scheduled Task script generation

Published Mar 3, 2026
GHSA-c276-fj82-f2pq

ApostropheCMS: Information Disclosure via choices/counts Query Parameters Bypassing publicApiProjection Field Restrictions

Published Apr 16, 2026
CVE-2026-27970

Angular i18n vulnerable to Cross-Site Scripting

Published Feb 27, 2026
CVE-2026-31862

@siteboon/claude-code-ui is Vulnerable to Command Injection via Multiple Parameters

Published Mar 11, 2026
GHSA-fvx6-pj3r-5q4q

OpenClaw's complex interpreter pipelines could skip exec script preflight validation

Published Apr 6, 2026
CVE-2021-27524MEDIUM

Margox Braft-Editor Cross-site Scripting Vulnerability

Published Aug 11, 2023
CVE-2018-16474MEDIUM

Stored Cross-Site Scripting in tianma-static

Published Nov 6, 2018
GHSA-gwhp-pf74-vj37

Fastify's connection header abuse enables stripping of proxy-added headers

Published Apr 16, 2026
CVE-2016-10680HIGH

Downloads Resources over HTTP in adamvr-geoip-lite

Published Sep 1, 2020
CVE-2025-53535

Better Auth Open Redirect Vulnerability in originCheck Middleware Affects Multiple Routes

Published Jul 7, 2025
CVE-2026-4867

path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters

Published Mar 27, 2026
GHSA-rf75-g96h-j3rm

Duplicate Advisory: OpenClaw's complex interpreter pipelines could skip exec script preflight validation

Published Apr 2, 2026
MAL-2024-8646

Malicious code in @diotoborg/suscipit-officia (npm)

Published Sep 2, 2024
MAL-2024-8647

Malicious code in @diotoborg/suscipit-vitae (npm)

Published Sep 2, 2024
CVE-2016-10673HIGH

ipip-coffee downloads Resources over HTTP

Published Feb 18, 2019
CVE-2021-26700HIGH

Remote code execution in vscode-npm-script

Published May 24, 2022
CVE-2026-28482

OpenClaw's unsanitized session ID enables path traversal in transcript file operations

Published Feb 18, 2026
CVE-2025-68157

webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects → SSRF + cache persistence

Published Feb 5, 2026
CVE-2020-28470HIGH

Cross-site Scripting (XSS) in @scullyio/scully

Published Apr 13, 2021
CVE-2020-6506MEDIUM

Android WebView Universal Cross-site Scripting

Published Oct 2, 2020
CVE-2008-6681MEDIUM

Cross-Site Scripting in dojo

Published Sep 1, 2020
CVE-2018-1999024MEDIUM

Macro in MathJax running untrusted Javascript within a web browser

Published Jul 27, 2018
CVE-2026-28363

OpenClaw's tools.exec.safeBins sort long-option abbreviation bypass can skip exec approval in allowlist mode

Published Mar 3, 2026
CVE-2018-1002204MEDIUM

Arbitrary File Write in adm-zip

Published Jul 27, 2018
CVE-2022-24717MEDIUM

Cross Site Scripting (XSS) in @finastra/ssr-pages

Published Mar 1, 2022
CVE-2026-0540

DOMPurify contains a Cross-site Scripting vulnerability

Published Mar 3, 2026
CVE-2025-69264

pnpm v10+ Bypass "Dependency lifecycle scripts execution disabled by default"

Published Jan 7, 2026
CVE-2026-28486

OpenClaw vulnerable to path traversal (Zip Slip) in archive extraction during explicit installation commands

Published Mar 2, 2026
CVE-2016-1000226

Cross-Site Scripting in swagger-ui

Published Sep 1, 2020
CVE-2026-3455

mailparser vulnerable to Cross-site Scripting

Published Mar 3, 2026
MAL-2024-9169

Malicious code in new-code-script-gt-a-samp-h-a-c-k-down-lo-ad-lkk02y (npm)

Published Oct 9, 2024
CVE-2025-62410

happy-dom's `--disallow-code-generation-from-strings` is not sufficient for isolating untrusted JavaScript

Published Oct 15, 2025
CVE-2026-32019

OpenClaw has incomplete IPv4 special-use SSRF blocking in web fetch guard

Published Mar 4, 2026
CVE-2026-33943

Happy DOM ECMAScriptModuleCompiler: unsanitized export names are interpolated as executable code

Published Mar 26, 2026
CVE-2026-23733

Lobe Chat affected by Cross-Site Scripting(XSS) that can escalate to Remote Code Execution(RCE)

Published Jan 20, 2026
CVE-2016-1000237MEDIUM

Cross-Site Scripting in sanitize-html

Published Apr 16, 2020
CVE-2021-41174MEDIUM

XSS vulnerability allowing arbitrary JavaScript execution

Published Nov 8, 2021
CVE-2015-6584MEDIUM

DataTable Vulnerable to Cross-Site Scripting

Published Aug 31, 2020
CVE-2013-2022MEDIUM

jplayer Cross Site Scripting vulnerability

Published May 17, 2022
CVE-2024-1648HIGH

Cross-site Scripting in electron-pdf

Published Feb 20, 2024
MAL-2024-9358

Malicious code in down-lo-ad-now-zip-mp3-sonic-nurse-a1wgm-jqylaq (npm)

Published Oct 16, 2024
MAL-2024-9359

Malicious code in down-lo-ad-now-zip-mp3-the-whole-love-f2ts8-cblkgz (npm)

Published Oct 16, 2024
MAL-2024-9362

Malicious code in down-load-available-zip-now-365509-chew-the-scenery-ymqd7-xaqqmu (npm)

Published Oct 16, 2024
CVE-2022-3783LOW

node-red-dashboard vulnerable to Cross-site Scripting

Published Nov 1, 2022
CVE-2022-24709HIGH

Cross site scripting in @awsui/components-react

Published Feb 25, 2022
MAL-2024-9382

Malicious code in mp3-file-zip-d-ownload-33971-the-imagination-stage-ar0bb-cvzjxl (npm)

Published Oct 16, 2024
CVE-2018-3771MEDIUM

statics-server Cross-site Scripting vulnerability

Published May 13, 2022
CVE-2023-23635MEDIUM

Jellyfin Web Cross-Site Scripting (XSS) via Collection Name

Published Feb 3, 2023
CVE-2025-64745

Astro development server error page is vulnerable to reflected Cross-site Scripting

Published Nov 13, 2025
CVE-2024-37145MEDIUM

Flowise Cross-site Scripting in /api/v1/chatflows-streaming/id

Published Aug 5, 2024
CVE-2022-29247LOW

Compromised child renderer processes could obtain IPC access without nodeIntegrationInSubFrames being enabled

Published Jun 16, 2022
CVE-2020-7691MEDIUM

Cross-site scripting in jspdf

Published May 11, 2021
CVE-2023-33831CRITICAL

A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA

Published Sep 18, 2023
CVE-2019-17495CRITICAL

Cross-site scripting in Swagger-UI

Published Oct 15, 2019
CVE-2021-23784MEDIUM

Cross-site Scripting in tempura

Published Nov 8, 2021
CVE-2020-8127MEDIUM

Cross-site Scripting in reveal.js

Published May 10, 2021
CVE-2024-21485MEDIUM

Dash apps vulnerable to Cross-site Scripting

Published Feb 2, 2024
CVE-2025-7339

on-headers is vulnerable to http response header manipulation

Published Jul 17, 2025
CVE-2020-7656MEDIUM

Cross-Site Scripting in jquery

Published May 20, 2020
CVE-2024-24556HIGH

@urql/next Cross-site Scripting vulnerability

Published Jan 30, 2024
CVE-2022-25873MEDIUM

Vuetify Cross-site Scripting vulnerability

Published Sep 19, 2022
CVE-2013-7454MEDIUM

Multiple XSS Filter Bypasses in validator

Published Oct 24, 2017
CVE-2024-34342HIGH

react-pdf vulnerable to arbitrary JavaScript execution upon opening a malicious PDF with PDF.js

Published May 7, 2024
CVE-2026-23888

pnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip)

Published Jan 26, 2026
CVE-2026-27492

Lettermint Node.js SDK leaks email properties to unintended recipients when client instance is reused

Published Feb 20, 2026
CVE-2024-29203MEDIUM

TinyMCE Cross-Site Scripting (XSS) vulnerability in handling iframes

Published Mar 26, 2024
CVE-2020-28360CRITICAL

Server-Side Request Forgery in private-ip

Published Apr 13, 2021
CVE-2019-16728MEDIUM

Cross-Site Scripting in dompurify

Published Aug 28, 2020
CVE-2019-16772LOW

Cross-Site Scripting in serialize-to-js

Published Dec 6, 2019
CVE-2021-32859MEDIUM

Baremetrics date range picker vulnerable to Cross-site Scripting

Published Feb 21, 2023
CVE-2020-4075MEDIUM

Arbitrary file read via window-open IPC in Electron

Published Jul 7, 2020
GHSA-w7j5-j98m-w679

OpenClaw has multiple E2E/test Dockerfiles that run all processes as root

Published Mar 3, 2026
CVE-2021-35513MEDIUM

Cross-site Scripting in Mermaid

Published Dec 10, 2021
CVE-2013-7370MEDIUM

methodOverride Middleware Reflected Cross-Site Scripting in connect

Published Aug 31, 2020
CVE-2015-3296MEDIUM

NodeBB Cross-site Scripting Vulnerability in Markdown Processing

Published May 17, 2022
CVE-2024-6783

vue-template-compiler vulnerable to client-side Cross-Site Scripting (XSS)

Published Jul 23, 2024
CVE-2026-32005

OpenClaw: Slack interactive callbacks could skip configured sender checks in some shared-workspace flows

Published Mar 4, 2026
CVE-2024-36423MEDIUM

Flowise Cross-site Scripting in /api/v1/public-chatflows/id

Published Aug 5, 2024
CVE-2022-23458MEDIUM

Toast UI Grid vulnerable to Cross-site Scripting

Published Sep 23, 2022
CVE-2022-25646MEDIUM

x-data-spreadsheet through 1.1.9 vulnerable to Cross-site Scripting

Published Aug 31, 2022
CVE-2019-10756MEDIUM

Cross-site Scripting in node-red-dashboard

Published Oct 25, 2019
CVE-2018-14042MEDIUM

Bootstrap Cross-site Scripting vulnerability

Published Sep 13, 2018
CVE-2026-32049

OpenClaw's inbound media downloads could exceed configured byte limits before rejection across multiple channels

Published Mar 2, 2026
CVE-2020-28487MEDIUM

Cross-site Scripting in vis-timeline

Published Apr 13, 2021
CVE-2020-15138HIGH

Cross-Site Scripting in Prism

Published Aug 7, 2020
GHSA-9r7h-6639-v5mw

Cross-Site Scripting in bootstrap-select

Published Sep 3, 2020
CVE-2020-11021MEDIUM

Http request which redirect to another hostname do not strip authorization header in @actions/http-client

Published Apr 29, 2020
CVE-2018-3786CRITICAL

Command Injection in egg-scripts

Published Sep 17, 2018
GHSA-vr7g-88fq-vhq3

Paperclip: OS Command Injection via Execution Workspace cleanupCommand

Published Apr 16, 2026
CVE-2018-3726MEDIUM

Cross-site Scripting (XSS) - Stored in crud-file-server

Published Jul 18, 2018
CVE-2023-47620MEDIUM

Scrypted Cross-site Scripting vulnerability

Published Aug 5, 2024
CVE-2022-24814HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in directus

Published Apr 5, 2022
CVE-2021-37700MEDIUM

Clipboard-based DOM-XSS

Published Aug 12, 2021
MAL-2022-2659

Malicious code in eclipse-typescript (npm)

Published Jun 20, 2022
GHSA-xpcf-pg52-r92g

Hono has incorrect IP matching in ipRestriction() for IPv4-mapped IPv6 addresses

Published Apr 8, 2026
CVE-2021-23411MEDIUM

Cross-site scripting in anchorme

Published Jul 26, 2021
GHSA-cxmw-p77q-wchg

OpenClaw: Arbitrary code execution via unvalidated WebView JavascriptInterface

Published Mar 26, 2026
CVE-2022-1330MEDIUM

Cross-site Scripting in fullpage.js

Published Apr 13, 2022
CVE-2022-21802MEDIUM

grapesjs before 0.19.5 vulnerable to Cross-site Scripting

Published Jul 26, 2022
CVE-2024-53441

Bit flip attack vulnerability in cookie-encrypter

Published Dec 9, 2024
CVE-2017-0931MEDIUM

Cross-Site Scripting in html-janitor

Published Nov 9, 2018
CVE-2021-23445LOW

Cross site scripting in datatables.net

Published Sep 29, 2021
MAL-2022-4370

Malicious code in lodashsiplainobjet (npm)

Published Aug 19, 2022
CVE-2025-69874

nanotar is vulnerable to path traversal in parseTar() and parseTarGzip()

Published Feb 11, 2026
CVE-2019-16769MEDIUM

Cross-Site Scripting in serialize-javascript

Published Dec 5, 2019
CVE-2021-42648MEDIUM

Cross site scripting in code-server

Published May 12, 2022
CVE-2026-32770

Parse Server LiveQuery subscription with invalid regular expression crashes server

Published Mar 17, 2026
CVE-2021-23484CRITICAL

Exposure of Resource to Wrong Sphere in Zip-Local

Published Feb 1, 2022
CVE-2021-32684MEDIUM

Missing Handler in @scandipwa/magento-scripts

Published Jun 21, 2021
MAL-2022-2284

Malicious code in custom-script-vanilla-js (npm)

Published Jun 20, 2022
CVE-2024-46976

@backstage/plugin-techdocs-backend vulnerable to circumvention of cross site scripting protection

Published Sep 17, 2024
CVE-2021-3780MEDIUM

Cross-site Scripting in peertube

Published Sep 20, 2021
CVE-2022-39300HIGH

Signature bypass via multiple root elements

Published Oct 12, 2022
CVE-2024-29881MEDIUM

TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements

Published Mar 26, 2024
MAL-2022-3076

Malicious code in flipper-plugin-ribtree (npm)

Published Jun 20, 2022
CVE-2026-25754

AdonisJS multipart body parsing has Prototype Pollution issue

Published Feb 6, 2026
CVE-2022-1291MEDIUM

Cross-site Scripting in tableexport.jquery.plugin

Published Apr 11, 2022
CVE-2019-5457MEDIUM

Cross-Site Scripting in min-http-server

Published Jul 31, 2019
CVE-2025-8082

Vuetify has a Cross-site Scripting (XSS) vulnerability in the VDatePicker component

Published Dec 12, 2025
MAL-2024-11043

Malicious code in github-script (npm)

Published Nov 27, 2024
MAL-2022-4260

Malicious code in launchdarkly-api-typescript-sample (npm)

Published Jun 20, 2022
GHSA-w8hx-hqjv-vjcq

Paperclip: Malicious skills able to exfiltrate and destroy all user data

Published Apr 16, 2026
CVE-2023-30094MEDIUM

Cross-site scripting in TotalJS

Published May 4, 2023
CVE-2024-38357MEDIUM

TinyMCE Cross-Site Scripting (XSS) vulnerability using noscript elements

Published Jun 19, 2024
CVE-2026-33349

Entity Expansion Limits Bypassed When Set to Zero Due to JavaScript Falsy Evaluation in fast-xml-parser

Published Mar 19, 2026
CVE-2022-0401CRITICAL

Path Traversal in w-zip

Published Feb 2, 2022
CVE-2020-10544MEDIUM

Cross-site Scripting in PrimeFaces

Published May 7, 2021
GHSA-wxw2-rwmh-vr8f

electerm: electerm_install_script_CommandInjection Vulnerability Report

Published Apr 16, 2026
CVE-2013-7035

Cross-Site Scripting in react

Published Sep 4, 2020
GHSA-5847-rm3g-23mw

OpenClaw has hook auth rate limiter bypass via IPv4-mapped IPv6 client key variants

Published Mar 3, 2026
CVE-2025-9287

cipher-base is missing type checks, leading to hash rewind and passing on crafted data

Published Aug 21, 2025
CVE-2026-33660

n8n has Multiple Remote Code Execution Vulnerabilities in Merge Node AlaSQL SQL Mode

Published Mar 25, 2026
CVE-2018-16459MEDIUM

Cross-Site Scripting in exceljs

Published Sep 11, 2018
CVE-2026-27612

repostat: Reflected Cross-Site Scripting (XSS) via repo prop in RepoCard

Published Feb 25, 2026
CVE-2021-27191HIGH

Denial of Service in get-ip-range

Published Apr 13, 2021
CVE-2016-1000235

fuelux vulnerable to Cross-Site Scripting in Pillbox feature

Published Sep 1, 2020
GHSA-5c6j-r48x-rmvq

Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()

Published Feb 28, 2026
CVE-2021-23447MEDIUM

Cross-site Scripting in teddy

Published Oct 12, 2021
MAL-2025-2245

Malicious code in chocolatechipjs-shopify (npm)

Published Mar 11, 2025
MAL-2024-9352

Malicious code in down-lo-ad-now-zip-mp3-149132-the-soft-cavalry-vhx8d-iuyuef (npm)

Published Oct 16, 2024
GHSA-xfqj-r5qw-8g4j

Paperclip: Unauthenticated Access to Multiple API Endpoints in Authenticated Mode

Published Apr 16, 2026
MAL-2025-192279

Malicious code in elf-stats-candystriped-chimney-879 (npm)

Published Dec 3, 2025
GHSA-j8j5-7r4h-vj2g

DbGate has cross site scripting via the SVG Icon String Handler component

Published Apr 13, 2026
CVE-2026-21894

n8n's Missing Stripe-Signature Verification Allows Unauthenticated Forged Webhooks

Published Jan 7, 2026
CVE-2026-33940

Handlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial

Published Mar 27, 2026
CVE-2026-26862

CleverTap Web SDK is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage

Published Feb 27, 2026
CVE-2025-52662

Nuxt DevTools vulnerable to cross-site scripting (XSS)

Published Nov 7, 2025
GHSA-xphh-5v4r-r3rx

PsiTransfer has Zip Slip Path Traversal via TAR Archive Download

Published Dec 30, 2025
CVE-2019-5422MEDIUM

Cross-Site Scripting in buttle

Published Apr 8, 2019
CVE-2021-23391HIGH

Calipso Arbitrary File Write via Archive Extraction (Zip Slip)

Published Jun 8, 2021
CVE-2019-5458MEDIUM

Cross-Site Scripting in http-file-server

Published Jul 31, 2019
CVE-2020-7747MEDIUM

Cross-site Scripting in lightning-server

Published May 10, 2021
MAL-2025-3826

Malicious code in defipulse-adapters (npm)

Published May 15, 2025
GHSA-xq3g-m3j8-2vmm

Duplicate Advisory: OpenClaw's inbound media downloads could exceed configured byte limits before rejection across multiple channels

Published Mar 21, 2026
MAL-2026-3036

Malicious code in uipath-ui-widgets (npm)

Published Apr 25, 2026
CVE-2018-6341MEDIUM

Cross-Site Scripting in react-dom

Published Jan 4, 2019
GHSA-m6fx-m8hc-572m

OpenClaw: Telegram audio preflight transcription enables resource consumption by unauthorized senders

Published Apr 3, 2026
MAL-2026-2804

Malicious code in transcript-viewer-ui-demo (npm)

Published Apr 16, 2026
MAL-2026-2910

Malicious code in tailwindthml-flips (npm)

Published Apr 15, 2026
CVE-2025-31119

generator-jhipster-entity-audit vulnerable to Unsafe Reflection when having Javers selected as Entity Audit Framework

Published Apr 4, 2025
CVE-2019-19596MEDIUM

GitBook allows Cross-site Scripting via a local .md file.

Published May 24, 2022
CVE-2023-38503MEDIUM

Incorrect Permission Checking for GraphQL Subscriptions

Published Jul 25, 2023
CVE-2019-12313MEDIUM

Cross-Site Scripting in shave

Published May 29, 2019
MAL-2025-191224

Malicious code in @fishingbooker/react-swiper (npm)

Published Nov 24, 2025
MAL-2026-3070

Malicious code in @tw-marionette/clipboard (npm)

Published Apr 26, 2026
CVE-2020-28249MEDIUM

Cross-site scripting in Joplin

Published May 10, 2021
CVE-2021-30074MEDIUM

Docsify vulnerable to cross-site scripting due to mishandled encoding

Published May 24, 2022
CVE-2022-2217MEDIUM

Cross site scripting in parse-url

Published Jun 28, 2022
CVE-2026-28459

OpenClaw has an arbitrary transcript path file write via gateway sessionFile

Published Feb 17, 2026
CVE-2013-4941MEDIUM

YUI Cross-site Scripting (XSS) vulnerability

Published May 13, 2022
MAL-2022-1313

Malicious code in azure-core-rest-pipeline (npm)

Published Jun 20, 2022
MAL-2022-1314

Malicious code in azure-core-rest-pipeline-js (npm)

Published Jun 20, 2022
MAL-2022-1315

Malicious code in azure-core-rest-pipeline-ts (npm)

Published Jun 20, 2022
CVE-2025-57330

web3-core-subscriptions has a Prototype Pollution vulnerability

Published Sep 24, 2025
MAL-2022-1582

Malicious code in bip174-bigint (npm)

Published Jun 20, 2022
CVE-2024-26318MEDIUM

Cross-site Scripting in Serenity

Published Feb 19, 2024
MAL-2022-1583

Malicious code in bipiy74902-wx1 (npm)

Published Jul 26, 2022
MAL-2025-192300

Malicious code in elf-stats-marzipan-cocoa-562 (npm)

Published Dec 4, 2025
CVE-2026-32978

OpenClaw: Unrecognized script runners could bypass `system.run` approval integrity

Published Mar 13, 2026
CVE-2018-16481MEDIUM

Cross-Site Scripting in html-pages

Published Feb 7, 2019
CVE-2026-28398

NocoDB Vulnerable to Stored Cross-Site Scripting via Comments and Rich Text Cells

Published Mar 3, 2026
CVE-2023-3691LOW

layui vulnerable to cross-site scripting

Published Jul 16, 2023
MAL-2022-1362

Malicious code in azure-pipelines-dependency-track (npm)

Published Jun 1, 2022
CVE-2019-16303CRITICAL

JHipster Kotlin using insecure source of randomness `RandomStringUtils` before v1.2.0

Published Jun 26, 2020
CVE-2019-14517MEDIUM

Cross-site Scripting in pandao editor.md

Published Aug 23, 2019
CVE-2026-32630

file-type: ZIP Decompression Bomb DoS via [Content_Types].xml entry

Published Mar 13, 2026
CVE-2021-23414MEDIUM

Cross-site Scripting in video.js

Published Aug 10, 2021
CVE-2021-31712MEDIUM

Cross-site Scripting in React Draft Wysiwyg

Published May 6, 2021
CVE-2018-5158HIGH

Malicious PDF can inject JavaScript into PDF Viewer

Published May 14, 2022
MAL-2025-2045

Malicious code in minipay-minidapps (npm)

Published Mar 3, 2025
CVE-2012-6662MEDIUM

jquery-ui Tooltip widget vulnerable to XSS

Published Oct 24, 2017
CVE-2018-18282MEDIUM

Next.js has cross site scripting (XSS) vulnerability via the 404 or 500 /_error page

Published Oct 15, 2018
CVE-2026-27670

OpenClaw: ZIP extraction race could write outside destination via parent symlink rebind

Published Mar 3, 2026
CVE-2012-6708MEDIUM

Cross-Site Scripting in jquery

Published Sep 1, 2020
CVE-2023-42399MEDIUM

Jodit Editor vulnerable to cross-site scripting

Published Sep 19, 2023
CVE-2020-27666MEDIUM

Cross-site Scripting in Strapi

Published Oct 29, 2020
CVE-2017-16202HIGH

cofeescript is malware

Published Aug 6, 2018
GHSA-82gw-wqw6-r2cf

Duplicate Advisory: Command Injection via unescaped environment assignments in Windows Scheduled Task script generation

Published Mar 19, 2026
CVE-2026-34210HIGH
Risk: 40.51/100

mppx has Stripe charge credential replay via missing idempotency check

Published Mar 29, 2026
CVE-2021-32808HIGH

Widget feature vulnerability allowing to execute JavaScript code using undo functionality

Published Aug 23, 2021
CVE-2020-28498MEDIUM

Elliptic Uses a Broken or Risky Cryptographic Algorithm

Published Mar 8, 2021
CVE-2024-21910MEDIUM

Cross-site scripting vulnerability in TinyMCE plugins

Published Nov 2, 2021
CVE-2022-0341MEDIUM

Cross-site Scripting in vditor

Published Mar 15, 2022
CVE-2022-41376MEDIUM

Cross site scripting in Metro UI

Published Oct 11, 2022
CVE-2020-26870MEDIUM

Cross-site Scripting in dompurify

Published Dec 18, 2020
CVE-2026-31994

OpenClaw Windows Scheduled Task script generation allowed local command injection via unsafe cmd argument handling

Published Mar 3, 2026
CVE-2018-3717MEDIUM

Cross-Site Scripting in connect

Published Jul 26, 2018
CVE-2018-14040MEDIUM

Bootstrap vulnerable to Cross-Site Scripting (XSS)

Published May 13, 2022
CVE-2020-1026CRITICAL

Incorrect Calculation in the MSR JavaScript Cryptography Library

Published Jan 6, 2022
CVE-2018-20677MEDIUM

bootstrap Cross-site Scripting vulnerability

Published Jan 17, 2019
CVE-2024-11831MEDIUM

Cross-site Scripting (XSS) in serialize-javascript

Published Feb 10, 2025
CVE-2025-66028

OneUptime is Vulnerable to Privilege Escalation via Login Response Manipulation

Published Nov 25, 2025
CVE-2022-0350MEDIUM

Cross-site Scripting in vditor

Published Apr 1, 2022
CVE-2022-25854MEDIUM

tagify can pass a malicious placeholder to initiate the cross-site scripting (XSS) payload

Published Apr 30, 2022
GHSA-68qg-g8mg-6pr7

paperclip Vulnerable to Unauthenticated Remote Code Execution via Import Authorization Bypass

Published Apr 10, 2026
CVE-2026-33937

Handlebars.js has JavaScript Injection via AST Type Confusion

Published Mar 27, 2026
CVE-2026-32774

Vulnogram contains a stored cross-site scripting vulnerability in comment hypertext handling

Published Mar 16, 2026
MAL-2022-1969

Malicious code in code-snippet-frontend (npm)

Published Jun 20, 2022
CVE-2020-7690MEDIUM

Cross-site scripting in jspdf

Published May 17, 2021
CVE-2023-22477MEDIUM

mercurius has Uncaught Exception when using subscriptions

Published Jan 9, 2023
CVE-2026-28472

OpenClaw's gateway connect could skip device identity checks when auth.token was present but not yet validated

Published Feb 17, 2026
MAL-2022-2101

Malicious code in com.unity.render-pipelines.high-definition-config (npm)

Published May 16, 2022
MAL-2022-2102

Malicious code in com.unity.scriptablebuildpipeline (npm)

Published Jun 20, 2022
CVE-2026-27183

OpenClaw: system.run wrapper-depth boundary could skip shell approval gating

Published Mar 9, 2026
CVE-2019-15478MEDIUM

Cross-Site Scripting in status-board

Published Sep 23, 2019
CVE-2020-7786CRITICAL

Command Injection in macfromip

Published Apr 12, 2021
CVE-2025-15599

DOMPurify contains a Cross-site Scripting vulnerability

Published Mar 3, 2026
CVE-2026-33508

Parse Server LiveQuery subscription query depth bypass

Published Mar 20, 2026
GHSA-9ppg-jx86-fqw7

Unauthorized npm publish of cline@2.3.0 with modified postinstall script

Published Feb 19, 2026
MAL-2022-269

Malicious code in @feiprotocol/fei-protocol-core (npm)

Published Jun 20, 2022
CVE-2024-57556

Cross Site Scripting vulnerability in store2

Published Jan 24, 2025
CVE-2013-7371MEDIUM

Node Connect Reflected Cross-Site Scripting in Sencha Labs Connect middleware

Published May 5, 2022
CVE-2023-26487MEDIUM

Vega has Cross-site Scripting vulnerability in `lassoAppend` function

Published Mar 2, 2023
MAL-2022-3639

Malicious code in hixletpaiprs (npm)

Published Aug 19, 2022
CVE-2020-7730CRITICAL

Command injection in bestzip

Published May 6, 2021
CVE-2020-28847MEDIUM

Cross site scripting in valine

Published Apr 6, 2022
MAL-2022-2657

Malicious code in eclipse-megamovie-build (npm)

Published Jun 20, 2022
CVE-2022-31175MEDIUM

CKEditor5 cross-site scripting vulnerability caused by the editor instance destroying process

Published Aug 6, 2022
CVE-2015-9286MEDIUM

Cross-site Scripting in NodeBB

Published May 1, 2019
CVE-2021-34435HIGH

Remote code execution in Eclipse Theia

Published Sep 2, 2021
CVE-2010-5312MEDIUM

Cross-site Scripting in jquery-ui

Published Oct 24, 2017
CVE-2021-32809MEDIUM

Clipboard feature vulnerability allowing to inject arbitrary HTML into the editor using paste functionality

Published Aug 23, 2021
CVE-2021-42227MEDIUM

Cross site scripting in kindeditor

Published Oct 18, 2021
CVE-2018-25053MEDIUM

Json2html vulnerable to cross-site scripting

Published Dec 28, 2022
CVE-2013-4940MEDIUM

YUI Cross-site Scripting (XSS) vulnerability

Published May 13, 2022
CVE-2024-21911MEDIUM

Cross-site scripting vulnerability in TinyMCE

Published Jan 6, 2021
CVE-2023-22491HIGH

gatsby-transformer-remark has possible unsanitized JavaScript code injection

Published Jan 11, 2023
MAL-2022-2142

Malicious code in competitive-equipment-icon (npm)

Published Jul 21, 2022
CVE-2019-14653MEDIUM

Cross-site Scripting in pandao

Published Aug 23, 2019
MAL-2022-4331

Malicious code in lliptiic (npm)

Published Aug 19, 2022
GHSA-7ggg-pvrf-458v

OpenClaw: PIP_INDEX_URL and UV_INDEX_URL bypass host exec env sanitization and redirect Python package-index traffic

Published Apr 2, 2026
MAL-2022-2475

Malicious code in dippy (npm)

Published Jun 20, 2022
MAL-2022-249

Malicious code in @epc-tools/typescript (npm)

Published Jun 20, 2022
CVE-2021-32854MEDIUM

textAngular Cross-site Scripting vulnerability

Published Feb 21, 2023
CVE-2025-43954

QMarkdown Cross-Site Scripting (XSS) vulnerability

Published Apr 20, 2025
CVE-2023-25571MEDIUM

Cross site scripting Vulnerability in backstage Software Catalog

Published Feb 14, 2023
GHSA-wpc6-37g7-8q4w

OpenClaw: Shell init-file options could satisfy exec allowlist script matching

Published Apr 7, 2026
CVE-2026-28357

NocoDB has Stored Cross-site Scripting via Formula Cell

Published Mar 2, 2026
MAL-2022-2951

Malicious code in eziparser (npm)

Published Aug 19, 2022
CVE-2021-21422HIGH

Cross-site scripting

Published Jun 28, 2021
MAL-2022-3657

Malicious code in holvipartners (npm)

Published May 31, 2022
CVE-2024-43407MEDIUM

Code Snippet GeSHi plugin in CKEditor 4 has reflected cross-site scripting (XSS) vulnerability

Published Aug 21, 2024
CVE-2026-27903

minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments

Published Feb 26, 2026
GHSA-w85g-3h6x-4xh2

OpenClaw: Image pixel-limit guard can fail open on sips and allow decompression-bomb DoS

Published Apr 3, 2026
CVE-2022-29172MEDIUM

Cross-site Scripting in Auth0 Lock

Published May 24, 2022
CVE-2022-0437MEDIUM

Cross-site Scripting in karma

Published Feb 6, 2022
MAL-2022-6327

Malicious code in strip-json-combmentd (npm)

Published Aug 19, 2022
MAL-2022-1675

Malicious code in brave-research-participation-tool (npm)

Published Jun 13, 2022
CVE-2026-32029

OpenClaw improperly parses X-Forwarded-For behind trusted proxies allows client IP spoofing in security decisions

Published Mar 3, 2026
CVE-2021-23673MEDIUM

Cross-site Scripting in pekeupload

Published Dec 2, 2021
GHSA-87v3-4cfp-cm76

Cross-Site Scripting (XSS) via SVG Schema innerHTML Injection in @pdfme/schemas

Published Mar 18, 2026
MAL-2022-1754

Malicious code in c6lipboady (npm)

Published Aug 19, 2022
CVE-2023-46495MEDIUM

Cross-site Scripting in evershop

Published Dec 8, 2023
CVE-2020-15270MEDIUM

receiving subscription objects with deleted session

Published Oct 27, 2020
CVE-2023-29641MEDIUM

editor.md vulnerable to Cross-site Scripting

Published May 1, 2023
MAL-2022-1930

Malicious code in clipobard (npm)

Published Aug 19, 2022
CVE-2023-32325MEDIUM

Potential for cross-site scripting in PostHog-js

Published May 22, 2023
CVE-2018-1002203MEDIUM

Arbitrary File Write via Archive Extraction in unzipper

Published Jul 27, 2018
MAL-2022-2815

Malicious code in eslint-plugin-flipper (npm)

Published Jun 20, 2022
CVE-2021-29489HIGH

Options structure open to Cross-site Scripting if passed unfiltered

Published May 6, 2021
GHSA-8986-v76q-8vr2

@keep-network/tbtc-v2 revealing P2PKH deposit with a wrapped P2SH script

Published Mar 2, 2026
GHSA-8cp7-rp8r-mg77

OpenClaw has SSRF guard bypass via IPv6 transition over ISATAP

Published Mar 4, 2026
CVE-2019-15482MEDIUM

Cross-Site Scripting in selectize-plugin-a11y

Published Aug 27, 2019
CVE-2019-12043MEDIUM

Cross-site Scripting in remarkable

Published May 29, 2019
MAL-2022-6714

Malicious code in typescript-action (npm)

Published Jun 20, 2022
MAL-2022-5053

Malicious code in okqaelhmbfuwipvz (npm)

Published Jul 11, 2022
MAL-2022-5072

Malicious code in on-running-script-context (npm)

Published Jun 8, 2022
GHSA-3pw3-v88x-xj24

Paperclip: Arbitrary File Read via Agent-Controlled adapterConfig.instructionsFilePath

Published Apr 16, 2026
MAL-2024-58

Malicious code in @linesearch/swiper (npm)

Published Jan 10, 2024
MAL-2024-7338

Malicious code in @zitterorg/quas-in-suscipit (npm)

Published Jul 4, 2024
CVE-2022-23461MEDIUM

Jodit Editor vulnerable to Cross-site Scripting

Published Sep 25, 2022
CVE-2024-34243MEDIUM

Konga is vulnerable to Cross Site Scripting (XSS) attacks

Published May 14, 2024
MAL-2022-6586

Malicious code in titanite-javascript (npm)

Published Jun 20, 2022
CVE-2020-22864MEDIUM

Cross site scripting in froala-editor

Published Oct 28, 2021
CVE-2022-38639MEDIUM

Markdown-Nice v1.8.22 vulnerable to Cross-site Scripting

Published Sep 10, 2022
CVE-2024-23724CRITICAL

Ghost has possible Cross-site Scripting issue

Published Feb 11, 2024
CVE-2026-33498

Parse Server has a query condition depth bypass via pre-validation transform pipeline

Published Mar 20, 2026
CVE-2022-23812CRITICAL

Embedded Malicious Code in node-ipc

Published Mar 16, 2022
MAL-2024-7414

Malicious code in @zitterorg/voluptatibus-suscipit (npm)

Published Jul 4, 2024
CVE-2021-23439MEDIUM

Cross-site Scripting in file-upload-with-preview

Published Sep 7, 2021
CVE-2023-26486MEDIUM

Vega Expression Language `scale` expression function Cross Site Scripting

Published Mar 2, 2023
MAL-2023-1070

Malicious code in @freestarcapital/collector-pipeline (npm)

Published Aug 9, 2023
GHSA-8g75-q649-6pv6

OpenClaw's system.run approvals did not bind mutable script operands across approval and execution

Published Mar 12, 2026
MAL-2024-9329

Malicious code in alb-um-availa-ble-zip-mp3-file-38068-its-all-about-to-change-rnonb-pzjjbh (npm)

Published Oct 16, 2024
MAL-2024-9363

Malicious code in down-load-available-zip-now-6092-expensive-shit-dzpv2-hzbnea (npm)

Published Oct 16, 2024
CVE-2019-11002MEDIUM

Materialize-css vulnerable to Cross-site Scripting in tooltip component

Published Apr 9, 2019
CVE-2026-30827

express-rate-limit: IPv4-mapped IPv6 addresses bypass per-client rate limiting on servers with dual-stack network

Published Mar 6, 2026
MAL-2024-7930

Malicious code in babel-preset-sofi-scripts (npm)

Published Aug 7, 2024
CVE-2022-27103MEDIUM

element-plus vulnerable to cross-site scripting (XSS) via el-table-column

Published Apr 26, 2022
CVE-2014-3743MEDIUM

Multiple Content Injection Vulnerabilities in marked

Published Aug 31, 2020
CVE-2015-8861MEDIUM

Cross-Site Scripting in handlebars

Published Oct 23, 2018
GHSA-9q8j-chc7-wpgp

Duplicate Advisory: OpenClaw session transcript files were created without forced user-only permissions

Published Mar 29, 2026
MAL-2025-1240

Malicious code in afip-example-api (npm)

Published Feb 7, 2025
CVE-2024-52809

vue-i18n has cross-site scripting vulnerability with prototype pollution

Published Dec 2, 2024
MAL-2023-425

Malicious code in fca-tpk-vip (npm)

Published Feb 27, 2023
CVE-2014-7192HIGH

Potential for Script Injection in syntax-error

Published Oct 24, 2017
CVE-2017-16206HIGH

cofee-script is malware

Published Aug 6, 2018
GHSA-gj9q-8w99-mp8j

OpenClaw: TOCTOU read in exec script preflight

Published Apr 16, 2026
MAL-2024-7109

Malicious code in @zitterorg/adipisci-dolore (npm)

Published Jul 4, 2024
MAL-2022-6715

Malicious code in typescript-dom-lib-generator (npm)

Published Jun 20, 2022
MAL-2022-6720

Malicious code in typescsdariptt (npm)

Published Jun 20, 2022
CVE-2019-15782MEDIUM

Cross-Site Scripting in webtorrent

Published Sep 4, 2019
GHSA-gjxx-92w9-8v8f

Clerk: SSRF in the opt-in clerkFrontendApiProxy feature may leak secret keys to unintended host

Published Mar 27, 2026
MAL-2022-6938

Malicious code in vipps-stitches (npm)

Published Jun 30, 2022
CVE-2025-62374

Parse Javascript SDK vulnerable to prototype pollution in `Parse.Object` and internal APIs

Published Oct 14, 2025
MAL-2024-7110

Malicious code in @zitterorg/adipisci-ipsum (npm)

Published Jul 4, 2024
MAL-2024-7111

Malicious code in @zitterorg/adipisci-quae-eius (npm)

Published Jul 4, 2024
MAL-2022-99

Malicious code in @azure-tests/perf-core-rest-pipeline (npm)

Published Jun 20, 2022
GHSA-gqqj-85qm-8qhf

Paperclip: codex_local inherited ChatGPT/OpenAI-connected Gmail and was able to send real email

Published Apr 16, 2026
MAL-2022-6606

Malicious code in toolbox-script (npm)

Published Jun 20, 2022
MAL-2024-8865

Malicious code in fma-connect-javascript (npm)

Published Sep 11, 2024
CVE-2017-18635MEDIUM

Cross-Site Scripting in @novnc/novnc

Published Aug 28, 2020
CVE-2017-16019MEDIUM

Cross-Site Scripting in gitbook

Published Sep 1, 2020
CVE-2019-17636HIGH

Insufficient Verification of Data Authenticity in Eclipse Theia

Published Apr 13, 2021
MAL-2024-9139

Malicious code in code-script-new-viking-simulator-script-hm9gi2 (npm)

Published Oct 9, 2024
CVE-2024-38356MEDIUM

TinyMCE Cross-Site Scripting (XSS) vulnerability using noneditable_regexp option

Published Jun 19, 2024
CVE-2016-10568HIGH

Downloads Resources over HTTP in geoip-lite-country

Published Feb 18, 2019
CVE-2025-2699

GetmeUK ContentTools Cross-Site Scripting (XSS)

Published Mar 24, 2025
GHSA-hgwr-wr8h-rxm7

Duplicate Advisory: OpenClaw: Google Chat app-url webhook auth accepted non-deployment add-on principals

Published Apr 10, 2026
MAL-2022-6627

Malicious code in trading-tips (npm)

Published Sep 26, 2022
CVE-2016-7103MEDIUM

jQuery-UI vulnerable to Cross-site Scripting in dialog closeText

Published Oct 24, 2017
CVE-2022-39239MEDIUM

@netlify/ipx vulnerable to Full Response SSRF and Stored XSS via Cache Poisoning and Improper Host Validation

Published Sep 21, 2022
MAL-2024-10548

Malicious code in @sportdigi/scripts (npm)

Published Nov 10, 2024
MAL-2022-6636

Malicious code in translationscripts (npm)

Published Jun 20, 2022
CVE-2025-67438

Sync-in Server has a stored cross-site scripting (XSS) vulnerability

Published Feb 20, 2026
GHSA-9x4v-xfq5-m8x5

Better Auth URL parameter HTML Injection (Reflected Cross-Site scripting)

Published Feb 5, 2025
MAL-2022-7330

Malicious code in yarn-design-system-rc-tooltip (npm)

Published Jun 20, 2022
MAL-2024-7148

Malicious code in @zitterorg/cum-ipsum-beatae (npm)

Published Jul 4, 2024
CVE-2018-3747MEDIUM

Cross-Site Scripting in public

Published Oct 10, 2018
MAL-2023-761

Malicious code in satellite-precipitation-detector (npm)

Published Jan 30, 2023
CVE-2022-0691CRITICAL

url-parse incorrectly parses hostname / protocol due to unstripped leading control characters.

Published Feb 22, 2022
MAL-2023-779

Malicious code in skip-validator (npm)

Published Jan 30, 2023
CVE-2025-29774

xml-crypto Vulnerable to XML Signature Verification Bypass via Multiple SignedInfo References

Published Mar 14, 2025
CVE-2025-1467

tarteaucitron Cross-site Scripting (XSS)

Published Feb 23, 2025
CVE-2023-26149MEDIUM

quill-mention Cross-site Scripting vulnerability

Published Sep 28, 2023
MAL-2023-75

Malicious code in a-love-letter-to-whiskey-by-kandi-steiner-on-iphone-new-version- (npm)

Published May 10, 2023
CVE-2012-5881MEDIUM

Cross-site scripting in yui 2.4.0

Published May 17, 2022
CVE-2022-31172HIGH

OpenZeppelin Contracts's SignatureChecker may revert on invalid EIP-1271 signers

Published Jul 21, 2022
MAL-2024-7250

Malicious code in @zitterorg/iusto-ipsum (npm)

Published Jul 4, 2024
MAL-2023-8537

Malicious code in node-common-npm-scripts (npm)

Published Nov 18, 2023
CVE-2024-47819

Umbraco CMS vulnerable to stored Cross-site Scripting in the "dictionary name" on Dictionary section

Published Oct 22, 2024
CVE-2025-31138

tarteaucitron.js allows UI manipulation via unrestricted CSS injection

Published Apr 7, 2025
MAL-2022-6717

Malicious code in typescript-snap (npm)

Published Jun 20, 2022
MAL-2022-6718

Malicious code in typescript3 (npm)

Published Jun 20, 2022
CVE-2019-8331MEDIUM

Bootstrap Vulnerable to Cross-Site Scripting

Published Feb 22, 2019
CVE-2023-37263MEDIUM

Strapi's field level permissions not being respected in relationship title

Published Sep 13, 2023
MAL-2024-7241

Malicious code in @zitterorg/ipsum-nam-facere (npm)

Published Jul 4, 2024
CVE-2017-16010MEDIUM

Cross-Site Scripting in i18next

Published Jul 24, 2018
CVE-2019-15603MEDIUM

Cross-Site Scripting in seeftl

Published Apr 1, 2020
CVE-2020-27224CRITICAL

Cross-site Scripting (XSS) in Eclipse Theia

Published Apr 13, 2021
CVE-2020-4051LOW

Cross-site Scripting in dijit editor's LinkDialog plugin

Published Jun 15, 2020
CVE-2022-39350MEDIUM

@dependencytrack/frontend vulnerable to Persistent Cross-Site-Scripting via Vulnerability Details

Published Oct 25, 2022
GHSA-8x4m-qw58-3pcx

mppx has multiple payment bypass and griefing vulnerabilities

Published Mar 29, 2026
CVE-2017-16022MEDIUM

Cross-Site Scripting in morris.js

Published Nov 9, 2018
GHSA-f37v-82c4-4x64

Electron: Crash in clipboard.readImage() on malformed clipboard image data

Published Apr 7, 2026
CVE-2021-29438MEDIUM

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in @nextcloud/dialogs

Published Apr 16, 2021
MAL-2024-11245

Malicious code in tripadvisor-npm (npm)

Published Dec 8, 2024
CVE-2018-9861MEDIUM

Enhanced Image plugin for CKEditor is vulnerable to Cross-site scripting (XSS)

Published May 14, 2022
MAL-2024-8114

Malicious code in @diotoborg/adipisci-placeat-iure (npm)

Published Sep 2, 2024
MAL-2024-8115

Malicious code in @diotoborg/adipisci-soluta (npm)

Published Sep 2, 2024
GHSA-g86v-f9qv-rh6m

OpenClaw SSRF guard misses four IPv6 special-use ranges

Published Mar 31, 2026
MAL-2024-1261

Malicious code in trip-component-platform-online-goto (npm)

Published Apr 15, 2024
GHSA-p7mm-r948-4q3q

Paperclip: Approval decision attribution spoofing via client-controlled `decidedByUserId` in paperclip server

Published Apr 16, 2026
CVE-2023-3620MEDIUM

tarteaucitron.js vulnerable to Cross-site Scripting

Published Jul 11, 2023
MAL-2024-1439

Malicious code in @juiggitea/ipsa-voluptatibus-velit (npm)

Published Jun 3, 2024
MAL-2024-8059

Malicious code in lodash-scripts (npm)

Published Aug 28, 2024
MAL-2024-8239

Malicious code in @diotoborg/dolore-magnam-ipsam (npm)

Published Sep 2, 2024
MAL-2024-1606

Malicious code in djangosnippets.org (npm)

Published Jun 13, 2024
CVE-2021-4231LOW

Angular vulnerable to Cross-site Scripting

Published May 27, 2022
CVE-2016-10537MEDIUM

Cross-Site Scripting in backbone

Published Feb 18, 2019
CVE-2024-51091

seajs Cross-site Scripting vulnerability

Published Mar 3, 2025
MAL-2024-8372

Malicious code in @diotoborg/ipsa-error (npm)

Published Sep 2, 2024
MAL-2024-9250

Malicious code in request-ip-validator (npm)

Published Oct 11, 2024
CVE-2026-24737

jsPDF has PDF Injection in AcroFormChoiceField that allows Arbitrary JavaScript Execution

Published Feb 2, 2026
MAL-2022-7075

Malicious code in web-scripts-monorepo (npm)

Published Jun 20, 2022
MAL-2024-10317

Malicious code in @gthwebdev/ui-tooltip (npm)

Published Nov 3, 2024
MAL-2024-8379

Malicious code in @diotoborg/ipsum-eaque-quidem (npm)

Published Sep 2, 2024
MAL-2024-1440

Malicious code in @juiggitea/ipsam-laborum-earum (npm)

Published Jun 3, 2024
MAL-2024-9330

Malicious code in alb-um-availa-ble-zip-mp3-file-46046-radical-connector-m2ydd-nirtvy (npm)

Published Oct 16, 2024
MAL-2024-9331

Malicious code in alb-um-availa-ble-zip-mp3-file-85058-bright-phoebus-dboqy-oraqvx (npm)

Published Oct 16, 2024
MAL-2024-9332

Malicious code in alb-um-availa-ble-zip-mp3-file-a-river-aint-too-much-to-love-0u85h-vysnxq (npm)

Published Oct 16, 2024
CVE-2015-1370MEDIUM

VBScript Content Injection in marked

Published Oct 24, 2017
MAL-2024-8574

Malicious code in @diotoborg/quo-adipisci-laboriosam (npm)

Published Sep 2, 2024
MAL-2024-9365

Malicious code in file-alb-um-zip-new-mp3-126009-bitter-sweet-dz7i2-hidryu (npm)

Published Oct 16, 2024
MAL-2024-1608

Malicious code in legacyreact-aws-s3-typescript (npm)

Published Jun 13, 2024
MAL-2024-9384

Malicious code in mp3-file-zip-d-ownload-7678-new-york-dolls-7j7ir-rschdh (npm)

Published Oct 16, 2024
MAL-2024-9385

Malicious code in mp3-file-zip-d-ownload-push-the-sky-away-m86s1-rigirm (npm)

Published Oct 16, 2024
CVE-2016-1000241

Cross-Site Scripting (XSS) in pivottable

Published Sep 1, 2020
MAL-2024-2377

Malicious code in flipper-plugins (npm)

Published Jun 25, 2024
MAL-2024-9193

Malicious code in updated-script-50-50-pick-a-door-script-rooms-check-vr6en2 (npm)

Published Oct 9, 2024
MAL-2024-9197

Malicious code in updated-script-retail-tycoon-2-script-h-a-c-k-9u9pw3 (npm)

Published Oct 9, 2024
CVE-2024-48948

Valid ECDSA signatures erroneously rejected in Elliptic

Published Oct 15, 2024
MAL-2024-9198

Malicious code in updated-script-roblox-muscle-legends-script-e3lrsz (npm)

Published Oct 9, 2024
CVE-2014-3742MEDIUM

File Descriptor Leak Can Cause DoS Vulnerability in hapi

Published Oct 24, 2017
CVE-2024-47080

Matrix JavaScript SDK's key history sharing could share keys to malicious devices

Published Oct 15, 2024
CVE-2022-39353CRITICAL

xmldom allows multiple root nodes in a DOM

Published Nov 1, 2022
CVE-2016-1000234

Cross-Site Scripting in jqtree

Published Sep 1, 2020
CVE-2023-3481MEDIUM

Critters Cross-site Scripting Vulnerability

Published Aug 11, 2023
CVE-2021-41086HIGH

Clipboard-based XSS

Published Sep 22, 2021
CVE-2017-16008MEDIUM

Cross-Site Scripting in i18next

Published Nov 9, 2018
GHSA-mp66-rf4f-mhh8

OpenClaw: Google Chat app-url webhook auth accepted non-deployment add-on principals

Published Mar 26, 2026
MAL-2024-8951

Malicious code in express-request-ip (npm)

Published Sep 23, 2024
CVE-2023-26108LOW

@nestjs/core vulnerable to Information Exposure via StreamableFile pipe

Published Mar 6, 2023
MAL-2024-8112

Malicious code in @diotoborg/adipisci-dolorum (npm)

Published Sep 2, 2024
CVE-2025-45001

react-native-keys insecurely stores encryption cipher and Base64 chunks

Published Jun 9, 2025
CVE-2019-18413LOW

SQL Injection and Cross-site Scripting in class-validator

Published Oct 12, 2021
MAL-2024-9152

Malicious code in get-new-script-viking-simulator-script-apo06a (npm)

Published Oct 9, 2024
MAL-2024-10968

Malicious code in eslint-config-sipplint (npm)

Published Nov 27, 2024
MAL-2024-8166

Malicious code in @diotoborg/autem-suscipit-unde (npm)

Published Sep 2, 2024
CVE-2021-36686MEDIUM

Cross-site Scripting in yapi-vendor

Published Jan 26, 2023
CVE-2020-7773MEDIUM

Cross-site Scripting in markdown-it-highlightjs

Published Feb 10, 2022
MAL-2025-1583

Malicious code in example-javascript (npm)

Published Feb 28, 2025
CVE-2021-43785HIGH

Cross-Site Scripting Vulnerability in @joeattardi/emoji-button

Published Dec 1, 2021
MAL-2024-9206

Malicious code in working-today--roblox-rise-of-nations-script-8ayh1b (npm)

Published Oct 9, 2024
CVE-2018-3748MEDIUM

Cross-Site Scripting in glance

Published Sep 27, 2018
CVE-2019-15600HIGH

Cross-Site Scripting in http_server

Published Mar 31, 2020
MAL-2022-873

Malicious code in adsscriptloaderstatic (npm)

Published Jun 20, 2022
MAL-2024-9386

Malicious code in mp3-file-zip-d-ownload-welcome-to-mali-ntp96-jgcurk (npm)

Published Oct 16, 2024
CVE-2021-23597HIGH

Uncaught Exception in fastify-multipart

Published Feb 11, 2022
GHSA-7gcj-phff-2884

Signal K Server has an Unauthenticated Regular Expression Denial of Service (ReDoS) via WebSocket Subscription Paths

Published Apr 21, 2026
CVE-2023-34840MEDIUM

angular-ui-notification Cross-site Scripting vulnerability

Published Jun 30, 2023
CVE-2021-41165HIGH

HTML comments vulnerability allowing to execute JavaScript code

Published Nov 17, 2021
CVE-2015-8862MEDIUM

Cross-Site Scripting in mustache

Published Oct 24, 2017
CVE-2024-23725MEDIUM

Cross-site Scripting in Ghost

Published Jan 21, 2024
CVE-2024-24815MEDIUM

CKEditor4 Cross-site Scripting vulnerability caused by incorrect CDATA detection

Published Feb 7, 2024
CVE-2021-41164HIGH

Advanced Content Filter (ACF) vulnerability allowing to execute JavaScript code using malformed HTML

Published Nov 17, 2021
CVE-2026-28393

OpenClaw's hook transform module path allows traversal and arbitrary JavaScript module loading

Published Mar 3, 2026
CVE-2026-26063

CediPay Affected by Improper Input Validation in Payment Processing

Published Feb 12, 2026
MAL-2024-7923

Malicious code in advertising-api-javascript-client (npm)

Published Aug 7, 2024
CVE-2023-47623MEDIUM

Scrypted Cross-site Scripting vulnerability

Published Aug 5, 2024
CVE-2014-10067MEDIUM

Validation Bypass in paypal-ipn

Published Aug 31, 2020
MAL-2025-47864

Malicious code in v-pure-tooltip (npm)

Published Sep 30, 2025
CVE-2026-30973

@appium/support has a Zip Slip arbitrary file write in its ZIP extraction

Published Mar 11, 2026
CVE-2026-23864

React Server Components have multiple Denial of Service Vulnerabilities

Published Jan 29, 2026
CVE-2021-23416MEDIUM

Cross-site Scripting in curly-bracket-parser

Published Aug 10, 2021
CVE-2025-14505

Elliptic Uses a Cryptographic Primitive with a Risky Implementation

Published Jan 8, 2026
GHSA-8796-gc9j-63rv

File upload local preview can run embedded scripts after user interaction

Published May 17, 2021
CVE-2026-4092

@google/clasp vulnerable to unsafe path traversal cloning or pulling a malicious script

Published Mar 13, 2026
CVE-2016-10563HIGH

Downloads Resources over HTTP in go-ipfs-dep

Published Feb 18, 2019
CVE-2021-23648MEDIUM

Cross-site Scripting in sanitize-url

Published Mar 17, 2022
MAL-2025-190724

Malicious code in @ensdomains/ccip-read-router (npm)

Published Nov 24, 2025
MAL-2025-190725

Malicious code in @ensdomains/ccip-read-worker-viem (npm)

Published Nov 24, 2025
CVE-2026-30948

Parse Server vulnerable to stored cross-site scripting (XSS) via SVG file upload

Published Mar 11, 2026
MAL-2025-48424

Malicious code in summerfi-typescript-config-security-notice (npm)

Published Oct 15, 2025
CVE-2016-1000227

Cross-Site Scripting in bootstrap-tagsinput

Published Sep 1, 2020
CVE-2022-25929MEDIUM

Smoothie vulnerable to Cross-site Scripting when tooltipLabel or strokeStyle are controlled by users

Published Dec 21, 2022
MAL-2023-281

Malicious code in dow-load-the-great-passage-by-shion-miura-on-ipad-full-edition- (npm)

Published May 10, 2023
MAL-2025-192327

Malicious code in elf-stats-candystriped-garland-735 (npm)

Published Dec 5, 2025
CVE-2022-0776MEDIUM

Cross site scripting in reveal.js

Published Mar 2, 2022
CVE-2025-31137

Remix and React Router allow URL manipulation via Host / X-Forwarded-Host headers

Published Apr 1, 2025
MAL-2025-48621

Malicious code in cypress-typescript (npm)

Published Oct 22, 2025
CVE-2018-19048MEDIUM

Cross-Site Scripting in simditor

Published May 14, 2019
CVE-2025-68949

n8n: Webhook Node IP Whitelist Bypass via Partial String Matching

Published Jan 13, 2026
MAL-2024-9194

Malicious code in updated-script-poop-with-friends-script-0rxgqp (npm)

Published Oct 9, 2024
MAL-2025-191329

Malicious code in @viapip/eslint-config (npm)

Published Nov 24, 2025
GHSA-j687-52p2-xcff

Astro: XSS in define:vars via incomplete </script> tag sanitization

Published Apr 21, 2026
MAL-2024-9196

Malicious code in updated-script-restaurant-tycoon-2-script-instant-cook-4dz6cj (npm)

Published Oct 9, 2024
MAL-2025-5001

Malicious code in ripe-grs (npm)

Published Jun 16, 2025
MAL-2023-447

Malicious code in flip-flop-flop (npm)

Published Jan 26, 2023
CVE-2024-47068

DOM Clobbering Gadget found in rollup bundled scripts that leads to XSS

Published Sep 23, 2024
CVE-2021-25978MEDIUM

Cross-site Scripting in apostrophe

Published Nov 10, 2021
MAL-2024-9205

Malicious code in working-today--find-the-simpsons-171-script-roblox-4zlhl1 (npm)

Published Oct 9, 2024
MAL-2024-9353

Malicious code in down-lo-ad-now-zip-mp3-18275-skelliconnection-taeie-mgpquk (npm)

Published Oct 16, 2024
MAL-2024-9355

Malicious code in down-lo-ad-now-zip-mp3-6766-the-empyrean-bn3pu-tdpbau (npm)

Published Oct 16, 2024
MAL-2025-191525

Malicious code in ripiocoin (npm)

Published Dec 1, 2025
MAL-2024-9356

Malicious code in down-lo-ad-now-zip-mp3-7514-tapestry-fqgk2-jvvwtn (npm)

Published Oct 16, 2024
MAL-2024-9357

Malicious code in down-lo-ad-now-zip-mp3-93-million-miles-psw9n-wbuosp (npm)

Published Oct 16, 2024
MAL-2025-48474

Malicious code in @upside/flex-common-typescript-lib (npm)

Published Oct 17, 2025
MAL-2024-9360

Malicious code in down-load-available-zip-now-23630-non-stop-je-te-plie-en-deux-6jxm0-xjqkwj (npm)

Published Oct 16, 2024
MAL-2024-9361

Malicious code in down-load-available-zip-now-35816-laughter-lust-jih3q-fajkvi (npm)

Published Oct 16, 2024
MAL-2025-5256

Malicious code in cow-scripts (npm)

Published Jun 25, 2025
CVE-2023-46499MEDIUM

Cross-site Scripting in evershop

Published Dec 8, 2023
MAL-2025-1940

Malicious code in stripe-sample-accept-a-payment (npm)

Published Mar 3, 2025
CVE-2019-15602MEDIUM

Cross-Site Scripting in fileview

Published Apr 1, 2020
MAL-2025-2185

Malicious code in node-unzip (npm)

Published Mar 5, 2025
CVE-2026-28453

OpenClaw has Zip Slip path traversal in tar archive extraction

Published Mar 2, 2026
CVE-2026-29608

OpenClaw's Node system.run approval hardening wrapper semantic drift can execute unintended local scripts

Published Mar 3, 2026
MAL-2025-192409

Malicious code in ecmascript-runtime-client (npm)

Published Dec 10, 2025
MAL-2026-2912

Malicious code in trgrip (npm)

Published Apr 15, 2026
CVE-2016-1000240

Cross-Site Scripting in c3

Published Sep 1, 2020
CVE-2026-26226

beautiful-mermaid contains an SVG attribute injection issue that can lead to cross-site scripting (XSS)

Published Feb 13, 2026
MAL-2026-1537

Malicious code in typescript-rtk-query (npm)

Published Mar 16, 2026
MAL-2025-192512

Malicious code in elf-stats-marzipan-cocoa-977 (npm)

Published Dec 11, 2025
MAL-2025-2584

Malicious code in vscode-typescript-next (npm)

Published Mar 20, 2025
MAL-2025-2609

Malicious code in eclipse-tractusx-github-io (npm)

Published Mar 24, 2025
CVE-2020-7750CRITICAL

Cross-Site Scripting in scratch-svg-renderer

Published Nov 9, 2020
CVE-2024-29504HIGH

Summernote vulnerable to cross-site scripting

Published Apr 11, 2024
MAL-2025-4838

Malicious code in javascript-heap (npm)

Published Jun 10, 2025
CVE-2022-45598MEDIUM

Joplin Desktop App vulnerable to Cross-site Scripting

Published Jan 31, 2023
CVE-2026-27121

Svelte affected by cross-site scripting via spread attributes in Svelte SSR

Published Feb 19, 2026
CVE-2016-10547MEDIUM

Cross-Site Scripting in nunjucks

Published Nov 6, 2018
MAL-2023-676

Malicious code in pdf-off-base-out-of-uniform-1-by-annabeth-albert-on-iphone-new-volumes- (npm)

Published May 10, 2023
MAL-2025-191119

Malicious code in kinvey-flex-scripts (npm)

Published Nov 24, 2025
CVE-2024-21535MEDIUM

Cross site scripting in markdown-to-jsx

Published Oct 15, 2024
CVE-2025-68115

Parse Server has a Cross-Site Scripting (XSS) vulnerability via Unescaped Mustache Template Variables

Published Dec 16, 2025
GHSA-fpw4-p57j-hqmq

Paperclip: Stored XSS via javascript: URLs in MarkdownBody — urlTransform override disables react-markdown sanitization

Published Apr 16, 2026
CVE-2026-22610

Angular has XSS Vulnerability via Unsanitized SVG Script Attributes

Published Jan 9, 2026
MAL-2025-2036

Malicious code in ct-connect-stripe (npm)

Published Mar 3, 2025
CVE-2017-16205HIGH

coffescript is malware

Published Aug 6, 2018
CVE-2025-65019

Astro Cloudflare adapter has Stored Cross-site Scripting vulnerability in /_image endpoint

Published Nov 19, 2025
CVE-2021-33295MEDIUM

Joplin Cross Site Scripting Vulnerability via NOSCRIPT tags

Published Jun 17, 2022
MAL-2025-4588

Malicious code in pancake_uniswap_validators_utils_snipe (npm)

Published May 29, 2025
CVE-2026-25141

Orval has Code Injection via unsanitized x-enum-descriptions using JS comments

Published Jan 30, 2026
CVE-2022-21830MEDIUM

Cross-site Scripting in @rocket.chat/livechat

Published Apr 3, 2022
CVE-2026-33951
Risk: 0.09/100

Signal K Server: Unauthenticated Source Priorities Manipulation

Published Apr 3, 2026
CVE-2020-7642MEDIUM

Cross-site scripting in lazysizes

Published Dec 10, 2021
CVE-2021-32660MEDIUM

Script injection

Published Jun 4, 2021
MAL-2026-636

Malicious code in idv-script (npm)

Published Feb 2, 2026
MAL-2026-1704

Malicious code in date-fns-scripts (npm)

Published Mar 18, 2026
CVE-2024-45389MEDIUM

DOM clobbering could escalate to Cross-site Scripting (XSS)

Published Sep 3, 2024
MAL-2026-734

Malicious code in xpack-subscription-test (npm)

Published Feb 4, 2026
CVE-2020-8823MEDIUM

Cross-site scripting in SocksJS-node

Published Apr 13, 2021
MAL-2025-2459

Malicious code in coral-typescript-types-pieces (npm)

Published Mar 17, 2025
GHSA-hhff-fj5f-qg48

OpenClaw runs Discord audio preflight transcription before member authorization

Published Apr 3, 2026
CVE-2024-42515CRITICAL

Glossarizer Cross-site Scripting vulnerability

Published Oct 31, 2024
MAL-2022-5811

Malicious code in rippled-exporter (npm)

Published Jun 20, 2022
CVE-2022-1726MEDIUM

Cross-site Scripting in bootstrap-table

Published May 17, 2022
MAL-2022-3054

Malicious code in firestore-stripe-payments-js (npm)

Published Jun 20, 2022
MAL-2025-2700

Malicious code in react-script-log (npm)

Published Mar 25, 2025
CVE-2022-4942LOW

eslint-detailed-reporter vulnerable to cross-site scripting

Published Apr 20, 2023
CVE-2026-22175

OpenClaw's exec allow-always can be bypassed via unrecognized multiplexer shell wrappers (busybox/toybox sh -c)

Published Mar 2, 2026
MAL-2025-2624

Malicious code in codex-cipher (npm)

Published Mar 24, 2025
CVE-2025-11183

QGIS QWC2 Cross-Site Scripting vulnerability

Published Oct 13, 2025
CVE-2019-19935MEDIUM

DOM-based cross-site scripting in Froala Editor

Published Feb 10, 2022
MAL-2022-3077

Malicious code in flipper-server-companion (npm)

Published Jul 29, 2022
CVE-2026-23947

Orval has a code injection via unsanitized x-enum-descriptions in enum generation

Published Jan 21, 2026
CVE-2021-32860MEDIUM

iziModal Cross-site Scripting vulnerability

Published Feb 21, 2023
MAL-2026-1424

Malicious code in @3stripes/api-client (npm)

Published Mar 15, 2026
CVE-2022-2079MEDIUM

Cross-site Scripting in NocoDB

Published Jun 15, 2022
CVE-2020-23849MEDIUM

Cross-site Scripting in jsoneditor

Published Oct 12, 2021
CVE-2022-48345MEDIUM

@braintree/sanitize-url Cross-site Scripting vulnerability

Published Feb 24, 2023
MAL-2022-3796

Malicious code in iiipkillkdeqcyh (npm)

Published Jun 20, 2022
MAL-2022-3852

Malicious code in instacart-javascript (npm)

Published Jun 20, 2022
CVE-2020-26272MEDIUM

IPC messages delivered to the wrong frame in Electron

Published Jan 28, 2021
MAL-2022-3868

Malicious code in internal-scripts (npm)

Published Jun 8, 2022
CVE-2023-41592MEDIUM

Froala Editor Cross-site Scripting vulnerability

Published Sep 15, 2023
CVE-2022-2932MEDIUM

Cross site scripting in mobiledoc-kit

Published Aug 23, 2022
CVE-2020-7660HIGH

Insecure serialization leading to RCE in serialize-javascript

Published Aug 11, 2020
CVE-2026-32098

Parse Server has a protected fields bypass via LiveQuery subscription WHERE clause

Published Mar 12, 2026
MAL-2022-6654

Malicious code in trip-tracker-web (npm)

Published Jun 20, 2022
GHSA-j965-2qgj-vjmq

JavaScript SDK v2 users should add validation to the region parameter value in or migrate to v3

Published Jan 8, 2026
MAL-2025-3736

Malicious code in com.unity.scripting.python (npm)

Published May 10, 2025
MAL-2026-2661

Malicious code in vip-landing (npm)

Published Apr 14, 2026
CVE-2019-9844MEDIUM

Cross-Site Scripting in simple-markdown

Published Apr 9, 2019
MAL-2026-788

Malicious code in @sporting-life/sportinglife-betslip-sdk (npm)

Published Feb 6, 2026
CVE-2026-30241

Mercurius's queryDepth limit bypassed for WebSocket subscriptions

Published Mar 6, 2026
CVE-2018-1000534MEDIUM

Joplin Vulnerable to Cross-site Scripting in Note Content

Published May 14, 2022
CVE-2020-7749HIGH

Injection and Cross-site Scripting in osm-static-maps

Published May 10, 2021
MAL-2026-2739

Malicious code in ccip-starter-kit-hardhat (npm)

Published Apr 16, 2026
MAL-2024-8982

Malicious code in djangosnippets (npm)

Published Sep 26, 2024
MAL-2026-1427

Malicious code in @3stripes/helpers (npm)

Published Mar 15, 2026
MAL-2026-1428

Malicious code in @3stripes/lib (npm)

Published Mar 15, 2026
CVE-2021-23472LOW

Cross-site Scripting in bootstrap-table

Published Nov 8, 2021
CVE-2022-29894MEDIUM

Cross-site Scripting in Strapi

Published Jun 14, 2022
CVE-2024-43368MEDIUM

Trix has a cross-site Scripting vulnerability on copy & paste

Published Aug 14, 2024
CVE-2021-23413MEDIUM

jszip Vulnerable to Prototype Pollution

Published Aug 10, 2021
MAL-2024-9302

Malicious code in ship_sleepnpm-tool (npm)

Published Oct 16, 2024
MAL-2026-1881

Malicious code in zip.js-2.8.2 (npm)

Published Mar 18, 2026
MAL-2024-9383

Malicious code in mp3-file-zip-d-ownload-7517-goodbye-yellow-brick-road-h63vl-tpdnhx (npm)

Published Oct 16, 2024
CVE-2020-8136HIGH

Uncontrolled Resource Consumption in fastify-multipart

Published May 6, 2021
CVE-2026-28361

NocoDB Missing Ownership Validation in MCP Token Operations

Published Mar 2, 2026
CVE-2023-25164HIGH

Sensitive Information leak via Script File in TinaCMS

Published Feb 8, 2023
CVE-2021-33041MEDIUM

Cross-site Scripting in vmd

Published Feb 10, 2022
CVE-2026-25054

n8n Has Stored Cross-site Scripting via Markdown Rendering in Workflow UI

Published Feb 4, 2026
CVE-2026-27485

OpenClaw: Reject symlinks in local skill packaging script

Published Feb 20, 2026
CVE-2022-48115MEDIUM

Cross-site Scripting in jspreadsheet

Published Feb 18, 2023
CVE-2026-24398

Hono IPv4 address validation bypass in IP Restriction Middleware allows IP spoofing

Published Jan 27, 2026
CVE-2022-25979MEDIUM

jSuites subect to Cross-site Scripting

Published Jan 31, 2023
MAL-2025-1462

Malicious code in ab-typescript-app (npm)

Published Feb 18, 2025
CVE-2026-28343

CKEditor 5 has Cross-site Scripting (XSS) in the HTML Support package

Published Mar 4, 2026
CVE-2026-26324

OpenClaw has a SSRF guard bypass via full-form IPv4-mapped IPv6 (loopback / metadata reachable)

Published Feb 17, 2026
CVE-2026-30587

Seafile Server has multiple stored XSS vulnerabilities

Published Mar 25, 2026
CVE-2025-3573

jquery-validation vulnerable to Cross-site Scripting

Published Apr 15, 2025
CVE-2023-48219MEDIUM

TinyMCE vulnerable to mutation Cross-site Scripting via special characters in unescaped text nodes

Published Nov 15, 2023
CVE-2023-26140MEDIUM

@excalidraw/excalidraw Cross-site Scripting vulnerability

Published Aug 16, 2023
GHSA-jxrq-8fm4-9p58

OpenClaw: Zip extraction symlink traversal could write outside destination

Published Mar 3, 2026
CVE-2023-37905MEDIUM

ckeditor-wordcount-plugin vulnerable to Cross-site Scripting in Source Mode of Editor

Published Jul 10, 2023
CVE-2026-25155

Qwik City CSRF protection middleware does not work properly for content type header with parameters (eg. multipart/form-data)

Published Feb 3, 2026
CVE-2023-22474HIGH

Parse Server option `masterKeyIps` vulnerability to IP spoofing

Published Jan 31, 2023
CVE-2026-33720

n8n Has Authorization Bypass in OAuth Callback via N8N_SKIP_AUTH_ON_OAUTH_CALLBACK

Published Mar 25, 2026
CVE-2024-9148

Flowise and Flowise Chat Embed vulnerable to Stored Cross-site Scripting

Published Sep 25, 2024
GHSA-vc8w-jr9v-vj7f

Withdrawn Advisory: Bootstrap Cross-Site Scripting (XSS) vulnerability

Published Jul 11, 2024
MAL-2024-7751

Malicious code in img-aws-s3-object-multipart-copy (npm)

Published Jul 15, 2024
CVE-2021-32855MEDIUM

Vditor Cross-site Scripting vulnerability

Published Feb 21, 2023
CVE-2020-7680MEDIUM

Cross-site Scripting in docsify

Published May 18, 2021
CVE-2017-16018MEDIUM

Cross-Site Scripting (XSS) in restify

Published Nov 9, 2018
CVE-2019-10062MEDIUM

Cross-site Scripting in aurelia-framework

Published Feb 10, 2022
CVE-2023-3672MEDIUM

webmention.js Cross-site Scripting vulnerability

Published Jul 14, 2023
CVE-2017-16015MEDIUM

Cross-Site Scripting in forms

Published Nov 9, 2018
CVE-2023-46494MEDIUM

Cross Site Scripting in evershop

Published Dec 8, 2023
MAL-2026-2717

Malicious code in @tax-taxdev/tools-scripts (npm)

Published Apr 16, 2026
MAL-2026-2718

Malicious code in @the-coca-cola-company/receipt-scanner-admin-lib (npm)

Published Apr 16, 2026
CVE-2020-28459HIGH

markdown-it-decorate vulnerable to cross-site scripting (XSS)

Published Jul 19, 2022
CVE-2020-8129CRITICAL

Code Injection in script-manager

Published Apr 13, 2021
MAL-2024-8479

Malicious code in @diotoborg/nostrum-nostrum-ipsum (npm)

Published Sep 2, 2024
CVE-2022-39299HIGH

Signature bypass via multiple root elements

Published Oct 12, 2022
CVE-2026-30048

NotChatbot WebChat has a stored cross-site scripting (XSS) vulnerability

Published Mar 18, 2026
CVE-2023-45885MEDIUM

NASA Open MCT Cross Site Scripting vulnerability

Published Nov 9, 2023
CVE-2024-43795MEDIUM

OpenC3 Cross-site Scripting in Login functionality (`GHSL-2024-128`)

Published Oct 2, 2024
CVE-2025-66648

`vega-functions` vulnerable to Cross-site Scripting via `setdata` function

Published Jan 5, 2026
MAL-2022-6328

Malicious code in strip-nasi (npm)

Published Aug 19, 2022
CVE-2025-14284

@tiptap/extension-link vulnerable to Cross-site Scripting (XSS)

Published Dec 9, 2025
MAL-2022-7394

Malicious code in zjdkvqcxmknipaye (npm)

Published Jul 12, 2022
CVE-2026-25723

Claude Code Vulnerable to Command Injection via Piped sed Command Bypasses File Write Restrictions

Published Feb 6, 2026
CVE-2020-7676MEDIUM

Angular vulnerable to Cross-site Scripting

Published Jun 18, 2020
CVE-2022-25863HIGH

Unsanitized JavaScript code injection possible in gatsby-plugin-mdx

Published Jun 3, 2022
MAL-2022-6976

Malicious code in vscode-npm-script (npm)

Published Jun 20, 2022
CVE-2024-4367HIGH

PDF.js vulnerable to arbitrary JavaScript execution upon opening a malicious PDF

Published May 7, 2024
CVE-2024-6485

Bootstrap Cross-Site Scripting (XSS) vulnerability for data-* attributes

Published Jul 11, 2024
CVE-2024-23841HIGH

@apollo/experimental-nextjs-app-support Cross-site Scripting vulnerability

Published Jan 30, 2024
MAL-2024-11975

Malicious code in eip-681-qr-generator (npm)

Published Dec 19, 2024
CVE-2022-29623HIGH

Connect-Multiparty allows arbitrary file upload

Published May 17, 2022
CVE-2025-66414

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

Published Dec 2, 2025
CVE-2026-32035

OpenClaw: Discord voice transcript owner-flag omission could expose owner-only tools in mixed-trust channels

Published Mar 3, 2026
CVE-2026-35409HIGH
Risk: 49.29/100

Directus: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in File Import

Published Apr 4, 2026
CVE-2021-30109MEDIUM

Cross-site Scripting in Froala Editor

Published Oct 6, 2021
MAL-2025-3134

Malicious code in valid-ip-scope (npm)

Published Apr 4, 2025
MAL-2022-6150

Malicious code in skip-reason-validator (npm)

Published Jun 20, 2022
MAL-2025-190723

Malicious code in @ensdomains/ccip-read-dns-gateway (npm)

Published Nov 24, 2025
CVE-2020-4072MEDIUM

Log Forging in generator-jhipster-kotlin

Published Jun 25, 2020
MAL-2025-191281

Malicious code in @oku-ui/tooltip (npm)

Published Nov 25, 2025
CVE-2018-3755MEDIUM

Cross-Site Scripting in sexstatic

Published Oct 1, 2018
MAL-2025-191526

Malicious code in silentcipherui (npm)

Published Dec 1, 2025
CVE-2022-30241MEDIUM

Cross-site Scripting in jquery.json-viewer

Published May 5, 2022
CVE-2026-0824

QuestDB UI's Web Console is Vulnerable to Cross-Site Scripting

Published Jan 10, 2026
MAL-2024-1207

Malicious code in payable-js-ipg-sdk (npm)

Published Apr 8, 2024
CVE-2014-7205HIGH

Arbitrary JavaScript Execution in bassmaster

Published Oct 24, 2017
CVE-2026-33941

Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options

Published Mar 27, 2026
CVE-2019-13127MEDIUM

mxGraph vulnerable to cross-site scripting in color field

Published May 24, 2022
CVE-2023-34459MEDIUM

OpenZeppelin Contracts using MerkleProof multiproofs may allow proving arbitrary leaves for specific trees

Published Jun 19, 2023
CVE-2019-13506MEDIUM

Cross-Site Scripting in @nuxt/devalue

Published Jul 16, 2019
CVE-2024-57041

NodeBB Cross-site scripting (XSS) vulnerability

Published Jan 24, 2025
MAL-2022-6333

Malicious code in stripe-ms (npm)

Published Jun 8, 2022
MAL-2022-6334

Malicious code in stripe-sample-checkout-with-multiple-locales (npm)

Published Jun 20, 2022
MAL-2022-6335

Malicious code in stripe-samples (npm)

Published Jun 20, 2022
CVE-2026-27739

Angular SSR is vulnerable to SSRF and Header Injection via request handling pipeline

Published Feb 25, 2026
MAL-2024-9400

Malicious code in zip-mp3-a-lbum-do-wnload-new-gift-of-screws-q2h3s-xswcix (npm)

Published Oct 16, 2024
MAL-2024-9401

Malicious code in zip-mp3-a-lbum-do-wnload-new-in-the-future-vrf78-daqfza (npm)

Published Oct 16, 2024
CVE-2026-3965

@whyour/qinglong: manipulation of the argument command leads to protection mechanism failure

Published Mar 12, 2026
MAL-2022-1109

Malicious code in arm-subscriptions (npm)

Published Jun 20, 2022
MAL-2025-2053

Malicious code in stripe-sample-accept-a-card-payment (npm)

Published Mar 3, 2025
CVE-2019-9737MEDIUM

Cross-Site Scripting in editor.md

Published Mar 14, 2019
MAL-2022-6367

Malicious code in suspicious-react-scripts (npm)

Published Jul 21, 2022
GHSA-qq9g-96v4-m3cj

Cross-Site Scripting (XSS) via Select Schema Option Value Injection in @pdfme/schemas

Published Mar 18, 2026
GHSA-wwrj-437c-ppq4

Duplicate Advisory: OpenClaw's system.run approvals did not bind mutable script operands across approval and execution

Published Mar 31, 2026
CVE-2024-48949

Elliptic's verify function omits uniqueness validation

Published Oct 10, 2024
MAL-2022-2153

Malicious code in conjure-receipe-example-app (npm)

Published Jun 20, 2022
GHSA-x7mm-9vvv-64w8

unhead: Streaming SSR `streamKey` injected into inline script without identifier validation

Published Apr 10, 2026
MAL-2025-4582

Malicious code in typescript-go (npm)

Published May 26, 2025
MAL-2025-2199

Malicious code in zz-aipage-widget (npm)

Published Mar 5, 2025
CVE-2026-27009

OpenClaw affected by Stored XSS in Control UI via unsanitized assistant name/avatar in inline script injection

Published Feb 18, 2026
CVE-2019-15607MEDIUM

Cross-Site Scripting in node-red

Published Jan 30, 2020
CVE-2020-15500MEDIUM

Cross-site scripting in TileServer GL

Published May 17, 2021
CVE-2025-63700

Clerk-js vulnerable to bypass of OAuth authentication flow by manipulating request at OTP verification stage

Published Nov 20, 2025
MAL-2025-191997

Malicious code in elf-stats-candystriped-hollyberry-986 (npm)

Published Dec 3, 2025
CVE-2013-4942MEDIUM

YUI Cross-site Scripting (XSS) vulnerability

Published May 13, 2022
CVE-2026-34451
Risk: 0.02/100

Claude SDK for TypeScript: Memory Tool Path Validation Allows Sandbox Escape to Sibling Directories

Published Apr 1, 2026
MAL-2022-324

Malicious code in @harrysforge/subscription-sdk (npm)

Published Jun 20, 2022
MAL-2025-48692

Malicious code in infobip-calls-showcase (npm)

Published Oct 22, 2025
MAL-2022-2154

Malicious code in conjure-typescript-runtime (npm)

Published Jun 20, 2022
MAL-2026-2708

Malicious code in @3stripes/toolkit (npm)

Published Apr 16, 2026
MAL-2025-3091

Malicious code in aiprofilestyle (npm)

Published Apr 3, 2025
CVE-2017-16128CRITICAL

npm-script-demo is malware

Published Sep 1, 2020
MAL-2025-192476

Malicious code in elf-stats-candystriped-muffin-773 (npm)

Published Dec 11, 2025
CVE-2010-2273MEDIUM

Cross-Site Scripting in dojo

Published Sep 11, 2019
CVE-2016-15025LOW

generator-hottowel Cross-site Scripting vulnerability

Published Feb 20, 2023
MAL-2022-1448

Malicious code in backbone-typescripts-accessor-generator (npm)

Published Jun 20, 2022
MAL-2025-3732

Malicious code in com.unity.render-pipelines.universal-config (npm)

Published May 11, 2025
CVE-2026-24764

OpenClaw Affected by Remote Code Execution via System Prompt Injection in Slack Channel Descriptions

Published Feb 17, 2026
CVE-2023-38687MEDIUM

Svelecte item names vulnerable to execution of arbitrary JavaScript

Published Aug 14, 2023
CVE-2021-32853MEDIUM

Erxes vulnerable to Cross-site Scripting

Published Feb 21, 2023
MAL-2022-2913

Malicious code in example-typescript (npm)

Published Jun 20, 2022
MAL-2022-3075

Malicious code in flipper-plugin-core (npm)

Published Sep 26, 2022
GHSA-6475-r3vj-m8vf

AWS SDK for JavaScript v3 adopted defense in depth enhancement for region parameter value

Published Jan 8, 2026
CVE-2024-45812MEDIUM

Vite DOM Clobbering gadget found in vite bundled scripts that leads to XSS

Published Sep 17, 2024
GHSA-8j7f-g9gv-7jhc

Duplicate Advisory: OpenClaw: SSRF via Unguarded Configured Base URLs in Multiple Channel Extensions (Incomplete Fix for CVE-2026-28476)

Published Apr 10, 2026
MAL-2022-4678

Malicious code in monday-integration-quickstart-app-typescript (npm)

Published Jun 20, 2022
CVE-2019-11003MEDIUM

Materialize-css vulnerable to Cross-site Scripting in autocomplete component

Published Apr 9, 2019
MAL-2024-8117

Malicious code in @diotoborg/alias-animi-suscipit (npm)

Published Sep 2, 2024
GHSA-89v5-38xr-9m4j

Postiz has Multiple SSRF Vectors - Webhooks, RSS Feed, URL Loader

Published Mar 27, 2026
GHSA-cjmm-f4jc-qw8r

DOMPurify ADD_ATTR predicate skips URI validation

Published Apr 3, 2026
GHSA-chm2-m3w2-wcxm

OpenClaw Google Chat spoofing access with allowlist authorized mutable email principal despite sender-ID mismatch

Published Feb 17, 2026
MAL-2024-8451

Malicious code in @diotoborg/necessitatibus-provident-adipisci (npm)

Published Sep 2, 2024
CVE-2025-3191

React Draft Wysiwyg Cross-Site Scripting (XSS) via the Embedded Button

Published Apr 4, 2025
CVE-2025-27793

Vega vulnerable to Cross-site Scripting via RegExp.prototype[@@replace]

Published Mar 27, 2025
CVE-2024-6484

Withdrawn Advisory: Bootstrap Cross-Site Scripting (XSS) vulnerability

Published Jul 11, 2024
MAL-2022-3528

Malicious code in guplip-util (npm)

Published Aug 19, 2022
CVE-2022-40440MEDIUM

mxGraph vulnerable to cross-site scripting in setTooltips function

Published Oct 12, 2022
CVE-2021-32661MEDIUM

Script injection

Published Jun 4, 2021
GHSA-jp4j-q5fc-58gv

OpenClaw's Discord component interaction ingress skips guild/channel policy enforcement

Published Mar 31, 2026
MAL-2025-192272

Malicious code in elf-stats-candystriped-ornament-933 (npm)

Published Dec 3, 2025
MAL-2022-2272

Malicious code in cthipjznlgrwqysa (npm)

Published Jul 11, 2022
CVE-2018-16484MEDIUM

Cross-Site Scripting in m-server

Published Feb 7, 2019
CVE-2024-34449MEDIUM

Vditor allows Cross-site Scripting via an attribute of an `A` element

Published May 3, 2024
CVE-2018-11093MEDIUM

Cross-Site Scripting in @ckeditor/ckeditor5-link

Published May 23, 2018
MAL-2025-3650

Malicious code in typescript-plugin-some-plugin (npm)

Published May 6, 2025
CVE-2026-21440

AdonisJS Path Traversal in Multipart File Handling

Published Jan 2, 2026
MAL-2022-6716

Malicious code in typescript-react-sample (npm)

Published Jun 20, 2022
MAL-2022-562

Malicious code in @riptano/helios (npm)

Published Jun 20, 2022
CVE-2019-20903MEDIUM

Cross-site scripting in @atlaskit/editor-core

Published Feb 10, 2022
MAL-2022-5695

Malicious code in reactnativeflipperexample (npm)

Published Jun 20, 2022
CVE-2020-27428MEDIUM

Cross-site Scripting in Scratch-Svg-Renderer

Published Jan 8, 2022
MAL-2022-6411

Malicious code in tackgqvipebdhxfy (npm)

Published Jul 11, 2022
MAL-2022-5810

Malicious code in rippleadminconsole (npm)

Published Dec 29, 2022
MAL-2025-48533

Malicious code in hash-script (npm)

Published Oct 21, 2025
CVE-2023-0410MEDIUM

@builder.io/qwik vulnerable to Cross-site Scripting

Published Jan 20, 2023
CVE-2026-27212

Prototype pollution in swiper

Published Feb 19, 2026
MAL-2025-191490

Malicious code in com.unity.sharp-zip-lib (npm)

Published Nov 29, 2025
MAL-2022-670

Malicious code in @trp-gims-usi-cip/web-portal-lib (npm)

Published Jul 5, 2022
MAL-2022-6700

Malicious code in twitch-desktop-ipc (npm)

Published Jun 20, 2022
MAL-2025-3098

Malicious code in fastly-ip-sync (npm)

Published Apr 3, 2025
CVE-2022-25869MEDIUM

Angular (deprecated package) Cross-site Scripting

Published Jul 16, 2022
CVE-2026-27495

n8n has a Sandbox Escape in its JavaScript Task Runner

Published Feb 25, 2026
MAL-2025-191998

Malicious code in elf-stats-candystriped-lantern-205 (npm)

Published Dec 3, 2025
MAL-2025-191999

Malicious code in elf-stats-candystriped-saddlebag-217 (npm)

Published Dec 3, 2025
MAL-2022-6680

Malicious code in tulip-backend (npm)

Published Jun 20, 2022
CVE-2022-2218MEDIUM

Cross site scripting in parse-url

Published Jun 28, 2022
MAL-2022-7234

Malicious code in wp-scripts (npm)

Published Jun 20, 2022
CVE-2020-8176MEDIUM

Cross-site scripting in @shopify/koa-shopify-auth

Published May 17, 2021
MAL-2025-192081

Malicious code in elf-stats-marzipan-fir-219 (npm)

Published Dec 3, 2025
MAL-2025-192082

Malicious code in elf-stats-marzipan-fir-795 (npm)

Published Dec 3, 2025
MAL-2025-4323

Malicious code in com.unity.multiplayer.tools (npm)

Published May 23, 2025
MAL-2025-4341

Malicious code in eslint-typescript-runtime-check (npm)

Published May 23, 2025
CVE-2019-16763MEDIUM

Pannellum Cross-Site Scripting due to data not being sanitized for URIs or vbscript

Published Nov 22, 2019
MAL-2025-3669

Malicious code in superhero-turnip (npm)

Published May 7, 2025
CVE-2021-37695HIGH

Fake objects feature vulnerability allowing to execute JavaScript code using malformed HTML.

Published Aug 23, 2021
MAL-2025-3889

Malicious code in flipper-plugin-preferences (npm)

Published May 16, 2025
MAL-2022-2492

Malicious code in discord-sniper (npm)

Published Jun 20, 2022
MAL-2022-6535

Malicious code in tetris-scripts (npm)

Published Jun 20, 2022
MAL-2022-2498

Malicious code in discord.js-aployscript-v11 (npm)

Published Jun 20, 2022
MAL-2025-4955

Malicious code in typescript-aurelia-api (npm)

Published Jun 14, 2025
MAL-2025-4551

Malicious code in aspirejavascript-vite (npm)

Published May 26, 2025
MAL-2025-192475

Malicious code in elf-stats-candystriped-cookiejar-799 (npm)

Published Dec 11, 2025
MAL-2025-192513

Malicious code in elf-stats-marzipan-nightcap-982 (npm)

Published Dec 11, 2025
MAL-2023-124

Malicious code in before-we-were-yours-by-lisa-wingate-on-iphone-new-chapters- (npm)

Published May 10, 2023
CVE-2016-1000233

Cross-Site Scripting in swagger-ui

Published Sep 1, 2020
GHSA-w5cr-2qhr-jqc5

Cloudflare Agents has a Reflected Cross-Site Scripting (XSS) vulnerability in AI Playground site

Published Feb 13, 2026
MAL-2023-1467

Malicious code in ynf-dx-scripts (npm)

Published Aug 14, 2023
MAL-2022-6719

Malicious code in typescsdaript (npm)

Published Jun 20, 2022
GHSA-265w-rf2w-cjh4

Paperclip: Privilege Escalation via Agent-Controlled workspaceStrategy.provisionCommand Leading to OS Command Execution

Published Apr 16, 2026
MAL-2025-4516

Malicious code in trip-plugins (npm)

Published May 27, 2025
CVE-2021-23370HIGH

Prototype Pollution in swiper

Published May 10, 2021
MAL-2025-4675

Malicious code in @sasmeee/ip-locator (npm)

Published Jun 4, 2025
MAL-2022-2658

Malicious code in eclipse-tslint (npm)

Published Jun 20, 2022
MAL-2025-48618

Malicious code in coreipc (npm)

Published Oct 25, 2025
CVE-2023-26491MEDIUM

rsshub vulnerable to Cross-site Scripting via unvalidated URL parameters

Published Mar 1, 2023
MAL-2023-531

Malicious code in int_stripe_sfra (npm)

Published Mar 29, 2023
MAL-2025-4863

Malicious code in pipreqs (npm)

Published Jun 10, 2025
MAL-2025-192955

Malicious code in eslint-config-pexip-engage (npm)

Published Dec 28, 2025
CVE-2022-23647HIGH

Cross-site Scripting in Prism

Published Feb 22, 2022
MAL-2023-604

Malicious code in mlp-friendship-map-mapping (npm)

Published Mar 31, 2023
CVE-2026-33938

Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block

Published Mar 27, 2026
MAL-2022-1189

Malicious code in awesomeypescriptxoader (npm)

Published Aug 19, 2022
MAL-2025-199

Malicious code in kubeflow-pipelines (npm)

Published Jan 20, 2025
GHSA-rhfg-j8jq-7v2h

OpenClaw: SSRF via Unguarded Configured Base URLs in Multiple Channel Extensions (Incomplete Fix for CVE-2026-28476)

Published Mar 29, 2026
CVE-2025-65098

Typebot affected by Credential Theft via Client-Side Script Execution and API Authorization Bypass

Published Jan 22, 2026
MAL-2022-706

Malicious code in @vividcortex/multiplexer (npm)

Published Jul 12, 2022
MAL-2025-2060

Malicious code in subscriptionmgmtserv (npm)

Published Mar 4, 2025
CVE-2021-23443MEDIUM

Cross-site Scripting in edge.js

Published Sep 22, 2021
MAL-2022-2208

Malicious code in cors-typescript-server (npm)

Published Jun 20, 2022
CVE-2021-33829MEDIUM

ckeditor4 vulnerable to cross-site scripting

Published Jun 21, 2021
GHSA-5ccf-884p-4jjq

Open WebUI Unauthenticated Multipart Boundary Denial of Service (DoS) Vulnerability

Published Mar 20, 2025
GHSA-5gqg-mqh5-2v39

Duplicate Advisory: OpenClaw Windows Scheduled Task script generation allowed local command injection via unsafe cmd argument handling

Published Mar 19, 2026
MAL-2023-8444

Malicious code in xterm-addon-clipboard (npm)

Published Nov 4, 2023
MAL-2024-1146

Malicious code in btcbip-39 (npm)

Published Mar 24, 2024
MAL-2023-878

Malicious code in the-universe-has-your-back-transform-fear-to-faith-by-gabrielle-bernstein-on-iphone-full-pages- (npm)

Published May 10, 2023
MAL-2025-48926

Malicious code in four-sdk-aes-ipheriv (npm)

Published Oct 28, 2025
CVE-2023-25572MEDIUM

Cross-Site-Scripting attack on `<RichTextField>`

Published Feb 14, 2023
MAL-2025-2301

Malicious code in code-snippet-editor-plugin (npm)

Published Mar 12, 2025
CVE-2018-14041MEDIUM

Bootstrap Cross-site Scripting vulnerability

Published Sep 13, 2018
MAL-2025-192474

Malicious code in elf-stats-candystriped-bauble-740 (npm)

Published Dec 11, 2025
CVE-2018-17574MEDIUM

Cross-site Scripting in yapi-vendor

Published Nov 21, 2018
CVE-2025-15265

svelte vulnerable to Cross-site Scripting

Published Jan 15, 2026
MAL-2022-7149

Malicious code in win32ipc (npm)

Published Oct 5, 2022
CVE-2022-35144MEDIUM

Raneto vulnerable to Cross-site Scripting

Published Aug 5, 2022
MAL-2025-2415

Malicious code in smart-power-strip (npm)

Published Mar 14, 2025
CVE-2019-20921MEDIUM

Cross-site scripting in bootstrap-select

Published May 7, 2021
CVE-2017-15881MEDIUM

Cross-Site Scripting in keystone

Published Nov 16, 2017
MAL-2024-10558

Malicious code in dancer-pipeline (npm)

Published Nov 8, 2024
CVE-2025-26791

DOMPurify allows Cross-site Scripting (XSS)

Published Feb 14, 2025
MAL-2024-1262

Malicious code in trip-component-platform-online-header (npm)

Published Apr 15, 2024
CVE-2024-53866

pnpm no-script global cache poisoning via overrides / `ignore-scripts` evasion

Published Dec 10, 2024
MAL-2022-3416

Malicious code in googleaips (npm)

Published Aug 19, 2022
CVE-2018-3773MEDIUM

metascraper before v5.2.0 vulnerable to stored cross-site scripting

Published Aug 8, 2018
CVE-2026-24769

NocoDB Vulnerable to Stored Cross-Site Scripting via SVG upload

Published Jan 28, 2026
MAL-2026-1429

Malicious code in @3stripes/ui (npm)

Published Mar 15, 2026
CVE-2020-15930MEDIUM

Cross-site Scripting in Joplin

Published May 7, 2021
CVE-2021-32850MEDIUM

@claviska/jquery-minicolors vulnerable to Cross-site Scripting

Published Feb 21, 2023
CVE-2026-1721

Cloudflare Agents is Vulnerable to Reflected Cross-Site Scripting in the AI Playground's OAuth callback handler

Published Feb 13, 2026
MAL-2026-1536

Malicious code in typescript-resolvers (npm)

Published Mar 16, 2026
CVE-2021-4103MEDIUM

vditor Vulnerable to Cross-site Scripting in SVG events

Published Jan 28, 2022
CVE-2024-28635MEDIUM

Cross-site scripting in Survey Creator

Published Mar 21, 2024
CVE-2023-41058HIGH

Trigger `beforeFind` not invoked in internal query pipeline when fetching pointer

Published Sep 4, 2023
MAL-2026-306

Malicious code in sd-cip-module-client (npm)

Published Jan 16, 2026
GHSA-xhq9-58fw-859p

ApostropheCMS: publicApiProjection Bypass via project Query Builder in Piece-Type REST API

Published Apr 16, 2026
MAL-2026-1554

Malicious code in typescript-validation-schema (npm)

Published Mar 16, 2026
CVE-2026-28359

NocoDB Vulnerable to Stored Cross-site Scripting via Rich Text Field

Published Mar 2, 2026
GHSA-w6wx-jq6j-6mcj

OpenClaw: pnpm dlx approvals did not bind local script operands

Published Apr 7, 2026
MAL-2026-583

Malicious code in vuejavascript (npm)

Published Jan 28, 2026
MAL-2026-634

Malicious code in eslint-config-minecraft-scripting (npm)

Published Feb 2, 2026
CVE-2023-22461HIGH

@mattkrick/sanitize-svg vulnerable to Cross-Site Scripting (XSS)

Published Jan 5, 2023
CVE-2013-7378CRITICAL

Potential Command Injection in hubot-scripts

Published Aug 31, 2020
CVE-2018-3716MEDIUM

Stored Cross-Site Scripting in simplehttpserver

Published Jul 26, 2018
MAL-2026-2703

Malicious code in @3stripes/components (npm)

Published Apr 16, 2026
MAL-2026-2704

Malicious code in @3stripes/config (npm)

Published Apr 16, 2026
MAL-2026-2705

Malicious code in @3stripes/core (npm)

Published Apr 16, 2026
MAL-2026-2706

Malicious code in @3stripes/sdk (npm)

Published Apr 16, 2026
MAL-2026-2707

Malicious code in @3stripes/shared (npm)

Published Apr 16, 2026
MAL-2022-4479

Malicious code in maps-api-for-javascript (npm)

Published Aug 2, 2022
GHSA-mwp6-j9wf-968c

Critical severity vulnerability that affects generator-jhipster

Published Sep 13, 2019
CVE-2026-25940

jsPDF has a PDF Injection in AcroForm module allows Arbitrary JavaScript Execution (RadioButton.createOption and "AS" property)

Published Feb 19, 2026
MAL-2026-2774

Malicious code in insomnia-scripting-environment (npm)

Published Apr 16, 2026
GSD-2022-1000008

faker.js 6.6.6 is broken and the developer has wiped the original GitHub repo

Published Jan 9, 2022
CVE-2023-41049HIGH

Improper Neutralization of Script in Attributes in @dcl/single-sign-on-client

Published Sep 4, 2023
CVE-2026-34778MEDIUM
Risk: 29.5/100

Electron: Service worker can spoof executeJavaScript IPC replies

Published Apr 3, 2026
MAL-2026-2829

Malicious code in paddle-internal-scripts (npm)

Published Apr 17, 2026
CVE-2026-22787

html2pdf.js contains a cross-site scripting vulnerability

Published Jan 14, 2026
MAL-2022-5342

Malicious code in pipeline-npm-artifactory (npm)

Published Jul 5, 2022
MAL-2022-819

Malicious code in accenture-react-scripts (npm)

Published Jun 20, 2022
MAL-2026-507

Malicious code in tripica-library (npm)

Published Jan 26, 2026
CVE-2017-16017MEDIUM

Cross-Site Scripting in sanitize-html

Published Nov 9, 2018
CVE-2023-4771MEDIUM

CKEditor cross-site scripting vulnerability in AJAX sample

Published Feb 7, 2024
MAL-2022-5427

Malicious code in postcssmipot (npm)

Published Aug 19, 2022
CVE-2018-6561MEDIUM

dijit editor cross-site scripting vulnerability

Published May 14, 2022
MAL-2024-8220

Malicious code in @diotoborg/deleniti-totam-suscipit (npm)

Published Sep 2, 2024
CVE-2026-34156CRITICAL
Risk: 51.23/100

NocoBase Affected by Sandbox Escape to RCE via console._stdout Prototype Chain Traversal in Workflow Script Node

Published Mar 30, 2026
MAL-2022-6194

Malicious code in snyk-azure-pipelines-task (npm)

Published Jun 20, 2022
CVE-2026-28401

NocoDB Vulnerable to Stored Cross-Site Scripting via Rich Text Cells

Published Mar 3, 2026
CVE-2024-37146MEDIUM

Flowise Cross-site Scripting in/api/v1/credentials/id

Published Aug 5, 2024
MAL-2022-6329

Malicious code in strip-umer (npm)

Published Jun 20, 2022
MAL-2022-6330

Malicious code in stripe-connect-rocketrides (npm)

Published May 31, 2022
MAL-2024-8387

Malicious code in @diotoborg/itaque-suscipit (npm)

Published Sep 2, 2024
CVE-2025-1647

Bootstrap Vulnerable to Cross-Site Scripting in its Popover and Tooltip Components

Published May 15, 2025
MAL-2024-9256

Malicious code in typescript-error-reporter-action (npm)

Published Oct 10, 2024
MAL-2024-8375

Malicious code in @diotoborg/ipsam-ad (npm)

Published Sep 2, 2024
CVE-2026-34043MEDIUM
Risk: 29.52/100

Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects

Published Mar 27, 2026
MAL-2023-273

Malicious code in dow-load-beautiful-tempest-malory-anderson-family-12-by-johanna-lindsey-on-iphone-new-form (npm)

Published May 10, 2023
MAL-2025-192477

Malicious code in elf-stats-candystriped-star-592 (npm)

Published Dec 11, 2025
MAL-2025-4640

Malicious code in blipkitgit (npm)

Published Jun 3, 2025
CVE-2026-28397

NocoDB Vulnerable to Stored Cross-site Scripting via Comments

Published Mar 3, 2026
CVE-2015-9251MEDIUM

Cross-Site Scripting (XSS) in jquery

Published Jan 22, 2018
MAL-2024-8374

Malicious code in @diotoborg/ipsa-ratione (npm)

Published Sep 2, 2024
MAL-2022-941

Malicious code in alipay-js-jdk (npm)

Published Jun 20, 2022
GHSA-rwwx-25m7-ww73

Duplicate Advisory: OpenClaw: Unrecognized script runners could bypass `system.run` approval integrity

Published Mar 29, 2026
MAL-2024-9100

Malicious code in o-typescript (npm)

Published Oct 5, 2024
MAL-2025-41450

Malicious code in @metadata-ipfs/bonk.fun-ipfs (npm)

Published Aug 28, 2025
MAL-2024-9098

Malicious code in m-typescript (npm)

Published Oct 5, 2024
MAL-2024-9148

Malicious code in get-new-script-rainbow-six-unlock-all-skins-elite-and-various-other-updated-2023-q6uukf (npm)

Published Oct 9, 2024
MAL-2024-9149

Malicious code in get-new-script-roblox-bedwars-script-076bmo (npm)

Published Oct 9, 2024
MAL-2024-9099

Malicious code in no-typescript (npm)

Published Oct 5, 2024
MAL-2024-9181

Malicious code in script-updated-gta-5-ragemp-spoofer-hwid-unban-zcnl0m (npm)

Published Oct 9, 2024
MAL-2024-9182

Malicious code in script-updated-roblox-redwood-prison-reworked-script-c5bqbv (npm)

Published Oct 9, 2024
CVE-2018-1000160MEDIUM

Cross-Site Scripting in @risingstack/protect

Published Apr 25, 2018
MAL-2022-1054

Malicious code in aployscript (npm)

Published Jun 20, 2022
MAL-2024-9354

Malicious code in down-lo-ad-now-zip-mp3-61269-billy-mann-9mfek-wlvmjv (npm)

Published Oct 16, 2024
CVE-2020-28455HIGH

markdown-it-toc Cross-site Scripting due to title of generated toc and contents of header not being escaped

Published Jul 26, 2022
CVE-2026-27700

Hono is Vulnerable to Authentication Bypass by IP Spoofing in AWS Lambda ALB conninfo

Published Feb 25, 2026
MAL-2023-139

Malicious code in born-to-win-find-your-success-by-zig-ziglar-on-iphone-new-version- (npm)

Published May 10, 2023
MAL-2025-1615

Malicious code in multipage-checkout (npm)

Published Feb 28, 2025
MAL-2026-1575

Malicious code in transform-typescript (npm)

Published Mar 16, 2026
MAL-2025-7740

Malicious code in @crimson-team/typescript-helpers (npm)

Published Aug 14, 2025
MAL-2023-122

Malicious code in beautiful-tempest-malory-anderson-family-12-by-johanna-lindsey-on-iphone-new-format- (npm)

Published May 10, 2023
MAL-2022-1482

Malicious code in bconffee-script (npm)

Published Aug 19, 2022
MAL-2025-7963

Malicious code in @frozen-team-qa/subscriptions-service (npm)

Published Aug 14, 2025
MAL-2022-2509

Malicious code in discord.js-selfbot-aployscript (npm)

Published Jun 20, 2022
MAL-2025-7977

Malicious code in @frozen-ui/tooltip (npm)

Published Aug 14, 2025
MAL-2023-580

Malicious code in managed-vip-2-by-kristen-callihan-on-iphone-full-volumes- (npm)

Published May 10, 2023
MAL-2023-1310

Malicious code in stripe-terminal-react-native (npm)

Published May 20, 2023
MAL-2022-3843

Malicious code in inipyrser (npm)

Published Aug 19, 2022
MAL-2022-1813

Malicious code in caliper-publish (npm)

Published Dec 12, 2022
MAL-2025-2765

Malicious code in identitydocumentserv-multipart-paypal (npm)

Published Mar 28, 2025
MAL-2026-3147

Malicious code in coinmate-typescript-client (npm)

Published Apr 29, 2026
MAL-2022-2197

Malicious code in core-rest-pipeline (npm)

Published Jun 20, 2022
MAL-2022-2206

Malicious code in cors-typescript (npm)

Published Jun 20, 2022
MAL-2022-4998

Malicious code in oabcipqvkhelzmrn (npm)

Published Jul 11, 2022
MAL-2024-1438

Malicious code in @juiggitea/ipsa-odit-illo (npm)

Published Jun 3, 2024
MAL-2026-783

Malicious code in adobe_pipeline_test (npm)

Published Feb 6, 2026
MAL-2025-4023

Malicious code in skip-tot (npm)

Published May 19, 2025
MAL-2025-4025

Malicious code in solana-sniper-bot (npm)

Published May 19, 2025
MAL-2023-163

Malicious code in cathode-versions-javascript (npm)

Published Jan 17, 2023
MAL-2023-203

Malicious code in compute-starter-kit-assemblyscript-default (npm)

Published May 25, 2023
MAL-2022-2776

Malicious code in equipment-color (npm)

Published Jul 21, 2022
MAL-2022-5829

Malicious code in rnx-kit-scripts (npm)

Published Jun 20, 2022
MAL-2023-245

Malicious code in designer-relationships-a-guide-to-happy-monogamy-positive-polyamory-and-optimistic-open-relationship (npm)

Published May 10, 2023
MAL-2022-4312

Malicious code in link-stripper2 (npm)

Published Jun 20, 2022
MAL-2024-1650

Malicious code in trip-component-platform-online-region-selector (npm)

Published Jun 20, 2024
MAL-2023-280

Malicious code in dow-load-the-best-we-could-do-by-thi-bui-on-ipad-new-format- (npm)

Published May 10, 2023
MAL-2023-303

Malicious code in elliptic-helper (npm)

Published Jun 13, 2023
MAL-2022-6180

Malicious code in smithy-typescript (npm)

Published Jun 20, 2022
MAL-2025-48591

Malicious code in chalk-ipheriv (npm)

Published Oct 24, 2025
MAL-2025-42153

Malicious code in moodle-core-tooltip (npm)

Published Sep 5, 2025
MAL-2023-865

Malicious code in the-best-we-could-do-by-thi-bui-on-ipad-new-format- (npm)

Published May 10, 2023
MAL-2022-6331

Malicious code in stripe-demo-connect-standard-saas-platform (npm)

Published Jul 25, 2022
MAL-2022-6332

Malicious code in stripe-identity-react-native (npm)

Published Jun 20, 2022
MAL-2024-12003

Malicious code in meu-script (npm)

Published Dec 19, 2024
MAL-2023-478

Malicious code in god-a-human-history-by-reza-aslan-on-ipad-new-version- (npm)

Published May 10, 2023
MAL-2022-6345

Malicious code in subscriptionid-apiversion (npm)

Published Jun 20, 2022
MAL-2023-504

Malicious code in hopelessly-devoted-bayou-devils-mc-1-by-am-myers-on-iphone-full-chapters- (npm)

Published May 10, 2023
MAL-2022-3635

Malicious code in hippocrates (npm)

Published Jun 20, 2022
MAL-2023-576

Malicious code in madly-whiskey-the-whiskeys-dark-knights-at-peaceful-harbor-2-by-melissa-foster-on-iphone-new-pages- (npm)

Published May 10, 2023
MAL-2022-6416

Malicious code in taniyadidipro (npm)

Published Oct 5, 2022
MAL-2022-2946

Malicious code in extratazip (npm)

Published Aug 19, 2022
MAL-2024-8113

Malicious code in @diotoborg/adipisci-esse-tempore (npm)

Published Sep 2, 2024
MAL-2022-342

Malicious code in @ibm-pipeline/logging (npm)

Published Jun 20, 2022
MAL-2022-3420

Malicious code in gopro-web-javascript-components (npm)

Published Jun 20, 2022
MAL-2026-1552

Malicious code in typescript-nhost (npm)

Published Mar 16, 2026
MAL-2023-748

Malicious code in rocketship-validator (npm)

Published Apr 20, 2023
MAL-2022-4859

Malicious code in njip (npm)

Published Aug 19, 2022
MAL-2022-6736

Malicious code in ucs-tooltip (npm)

Published Jun 20, 2022
MAL-2022-3521

Malicious code in gulptypscript (npm)

Published Aug 19, 2022
MAL-2025-2412

Malicious code in scriptconfig (npm)

Published Mar 14, 2025
MAL-2026-2009

Malicious code in repo-typescript-config (npm)

Published Mar 21, 2026
MAL-2026-2394

Malicious code in typescript-mock-data (npm)

Published Mar 24, 2026
MAL-2022-354

Malicious code in @immersive-composer/scripting-api (npm)

Published Jun 20, 2022
MAL-2025-2785

Malicious code in shipmentdetails-paypal (npm)

Published Mar 28, 2025
MAL-2025-2786

Malicious code in shipmenttrackingserv-paypal (npm)

Published Mar 28, 2025
MAL-2026-2579

Malicious code in @bookiply/core (npm)

Published Apr 13, 2026
MAL-2025-4991

Malicious code in azure-pipeline-filter (npm)

Published Jun 16, 2025
Check your entire dependency tree at onceRun dependency scan →