Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-8hgg-xxm5-3873: DOMPurify Open Redirect vulnerability

DOMPurify before 1.0.11 allows reverse tabnabbing in demos/hooks-target-blank-demo.html because links lack a ‘rel="noopener noreferrer"’ attribute.

ghsa
#vulnerability#git

DOMPurify Open Redirect vulnerability

Moderate severity GitHub Reviewed Published Nov 14, 2023 to the GitHub Advisory Database • Updated Nov 15, 2023

ghsa: Latest News

GHSA-vfpf-xmwh-8m65: ProsemirrorToHtml has a Cross-Site Scripting (XSS) vulnerability through unescaped HTML attribute values