Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Express Xss Sanitizer Project Subscribe
Filtered by product Express Xss Sanitizer
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-21169 1 Express Xss Sanitizer Project 1 Express Xss Sanitizer 2022-09-28 N/A 6.1 MEDIUM
The package express-xss-sanitizer before 1.1.3 are vulnerable to Prototype Pollution via the allowedTags attribute, allowing the attacker to bypass xss sanitization.