High severityNVD Advisory· Published Sep 11, 2015· Updated Jun 17, 2026
CVE-2015-6584
CVE-2015-6584
Description
Cross-site scripting (XSS) vulnerability in the DataTables plugin 1.10.8 and earlier for jQuery allows remote attackers to inject arbitrary web script or HTML via the scripts parameter to media/unit_testing/templates/6776.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
datatablesnpm | < 1.10.10 | 1.10.10 |
datatables/datatablesPackagist | < 1.10.10 | 1.10.10 |
Affected products
3- ghsa-coords2 versions
< 1.10.10+ 1 more
- (no CPE)range: < 1.10.10
- (no CPE)range: < 1.10.10
Patches
Vulnerability mechanics
References
12- www.netsparker.com/cve-2015-6384-xss-vulnerability-identified-in-datatables/nvdExploit
- github.com/advisories/GHSA-4mv4-gmmf-q382ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2015-6584ghsaADVISORY
- packetstormsecurity.com/files/133555/DataTables-1.10.8-Cross-Site-Scripting.htmlnvdWEB
- seclists.org/fulldisclosure/2015/Sep/37nvdWEB
- www.securityfocus.com/archive/1/536437/100/0/threadednvdWEB
- www.securityfocus.com/archive/1/archive/1/536437/100/0/threadedghsaWEB
- github.com/DataTables/DataTables/issues/602ghsaWEB
- github.com/DataTables/DataTablesSrc/commit/ccf86dc5982bd8e16dghsaWEB
- github.com/DataTables/DataTablesSrc/commits/1.10.10ghsaWEB
- www.netsparker.com/cve-2015-6384-xss-vulnerability-identified-in-datatablesghsaWEB
- www.npmjs.com/advisories/5ghsaWEB
News mentions
0No linked articles in our index yet.