CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
All versions of package materialize-css are vulnerable to Cross-site Scripting (XSS) due to improper escape of user input (such as <not-a-tag />) that is being parsed as HTML/JavaScript, and inserted into the Docum...Show more |
In Materialize through 1.0.0, XSS is possible via the Toast feature. |
In Materialize through 1.0.0, XSS is possible via the Autocomplete feature. |
In Materialize through 1.0.0, XSS is possible via the Tooltip feature. |