Medium severity5.4NVD Advisory· Published Apr 12, 2022· Updated Jun 17, 2026
CVE-2022-1330
CVE-2022-1330
Description
stored xss due to unsantized anchor url in GitHub repository alvarotrigo/fullpage.js prior to 4.0.4. stored xss .
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
fullpage.jsnpm | < 4.0.5 | 4.0.5 |
Affected products
3- alvarotrigo/alvarotrigo/fullpage.jsv5Range: unspecified
Patches
Vulnerability mechanics
References
5- github.com/alvarotrigo/fullpage.js/commit/e7a5db42711700c8a584e61b5e532a64039fe92bnvdPatchThird Party AdvisoryWEB
- huntr.dev/bounties/08d2a6d0-772f-4b05-834e-86343f263c35nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-h3cq-j957-vhxgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-1330ghsaADVISORY
- github.com/alvarotrigo/fullPage.js/pull/4360ghsaWEB
News mentions
0No linked articles in our index yet.