← Back

Spin.js

spin.js

1 CVE • 1 product

Products (1)

Click to collapse
Toggle
Spin.js
spin.js

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Spin.js
1Spin.js
Jun 17, 2026
Mar 11, 2026
2.0 LOW· v4
6.1 MEDIUM· v3
N/A· v2
Versions of the package spin.js before 3.0.0 are vulnerable to Cross-site Scripting (XSS) via the spin() function that allows a creation of more than 1 alert for each 'target' element. An attacker would need to set an ar...Show more
Versions of the package spin.js before 3.0.0 are vulnerable to Cross-site Scripting (XSS) via the spin() function that allows a creation of more than 1 alert for each 'target' element. An attacker would need to set an arbitrary key-value pair on Object.prototype through a crafted URL achieving a prototype pollution first, before being able to execute arbitrary JavaScript in the context of the user's browser.Show less