← Back

Scratch Svg Renderer

scratch-svg-renderer

Vendor: Mit • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mit
1Scratch Svg Renderer
Jun 17, 2026
Jan 6, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A DOM-based cross-site scripting (XSS) vulnerability in Scratch-Svg-Renderer v0.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted sb3 file.
1Mit
1Scratch Svg Renderer
Jun 17, 2026
Oct 21, 2020
N/A· v4
9.6 CRITICAL· v3
6.8 MEDIUM· v2
This affects the package scratch-svg-renderer before 0.2.0-prerelease.20201019174008. The loadString function does not escape SVG properly, which can be used to inject arbitrary elements into the DOM via the _transformMe...Show more
This affects the package scratch-svg-renderer before 0.2.0-prerelease.20201019174008. The loadString function does not escape SVG properly, which can be used to inject arbitrary elements into the DOM via the _transformMeasurements function.Show less