Medium severity6.1OSV Advisory· Published Mar 27, 2019· Updated Jun 17, 2026
CVE-2016-10744
CVE-2016-10744
Description
In Select2 through 4.0.5, as used in Snipe-IT and other products, rich selectlists allow XSS. This affects use cases with Ajax remote data loading when HTML templates are used to display listbox data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
select2npm | < 4.0.6 | 4.0.6 |
Affected products
7- ghsa-coords5 versionspkg:npm/select2pkg:apk/chainguard/nextcloud-server-33pkg:apk/wolfi/nextcloud-server-33pkg:apk/chainguard/nextcloud-server-32pkg:apk/wolfi/nextcloud-server-32
< 4.0.6+ 4 more
- (no CPE)range: < 4.0.6
- (no CPE)range: < 33.0.6-r9
- (no CPE)range: < 33.0.6-r9
- (no CPE)range: < 32.0.12-r5
- (no CPE)range: < 32.0.12-r5
Patches
Vulnerability mechanics
References
5- github.com/snipe/snipe-it/pull/6831nvdPatchThird Party AdvisoryWEB
- github.com/snipe/snipe-it/pull/6831/commits/5848d9a10c7d62c73ff6a3858edfae96a429402anvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-rf66-hmqf-q3fcghsaADVISORY
- github.com/select2/select2/issues/4587nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2016-10744ghsaADVISORY
News mentions
0No linked articles in our index yet.